Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Libxslt | — | Apply OS X security update 2008-007 | Dec 16, 2011 | May 23, 2008 |
| Apple Safari | — | Upgrade to Apple Safari version 3.2Uninstall Apple Safari on Windows | Jan 5, 2012 | May 23, 2008 |
| Debian | — | Upgrade libxslt | Jul 30, 2024 | May 23, 2008 |
| Gentoo Linux | — | Upgrade dev-libs/libxslt. | Oct 30, 2017 | May 23, 2008 |
| Oracle_linux | — | Upgrade libxsltUpgrade libxslt-develUpgrade libxslt-python | Oct 16, 2024 | May 23, 2008 |
| Suse | — | Upgrade libxslt-x86Upgrade libxslt-develUpgrade libxsltUpgrade libxslt1Upgrade libxslt-toolsUpgrade libxslt-devel-32bitUpgrade libexslt0Upgrade libxslt-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libxslt1.1 | Nov 8, 2024 | May 23, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub