libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxslt | Aug 30, 2017 | Apr 12, 2013 |
| Debian | — | Upgrade libxslt | Jul 30, 2024 | Apr 12, 2013 |
| Gentoo Linux | — | Upgrade dev-libs/libxslt. | Oct 30, 2017 | Apr 12, 2013 |
| Oracle Solaris | — | Upgrade library/python-2/libxsl-26 to version 1.1.26-0.175.1.11.0.4.0 on Solaris 11.1Upgrade library/python-2/libxsl-27 to version 1.1.26-0.175.1.11.0.4.0 on Solaris 11.1Upgrade library/libxslt to version 1.1.26-0.175.1.11.0.4.0 on Solaris 11.1 | May 29, 2017 | Apr 12, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 2, 2012 |
| Suse | — | Upgrade libxslt-pythonUpgrade libxsltUpgrade libxslt-32bitUpgrade libxslt-devel-32bitUpgrade libxslt-develUpgrade libxslt-x86 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libxslt1.1 | Nov 8, 2024 | Apr 12, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub