Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libxslt | Jul 30, 2024 | Aug 1, 2008 |
| Gentoo Linux | — | Upgrade dev-libs/libxslt. | Oct 30, 2017 | Aug 1, 2008 |
| Oracle_linux | — | Upgrade libxsltUpgrade libxslt-develUpgrade libxslt-python | Oct 16, 2024 | Aug 1, 2008 |
| Suse | — | Upgrade libxslt-64bitUpgrade libxslt-develUpgrade libxslt-devel-64bitUpgrade libxsltUpgrade libxslt-devel-32bitUpgrade suse-releaseUpgrade libxslt-32bit | Dec 12, 2013 | Aug 1, 2008 |
| Ubuntu | — | Upgrade libxslt1.1 | Nov 8, 2024 | Aug 1, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub