CVE-2011-1425

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.
References
Link Resource
http://git.gnome.org/browse/xmlsec/commit/?id=2d5eddcc4163ea050cf3a3a1a25452bb5124f780 Patch
http://git.gnome.org/browse/xmlsec/commit/?id=35eaacde6093d6711339754fc2146341b8b9f5fa Patch
http://secunia.com/advisories/43920 Vendor Advisory
http://secunia.com/advisories/44167
http://secunia.com/advisories/44423
http://trac.webkit.org/changeset/79159
http://www.aleksey.com/pipermail/xmlsec/2011/009120.html Patch
http://www.debian.org/security/2011/dsa-2219
http://www.mandriva.com/security/advisories?name=MDVSA-2011:063
http://www.redhat.com/support/errata/RHSA-2011-0486.html
http://www.securityfocus.com/bid/47135
http://www.securitytracker.com/id?1025284
http://www.vupen.com/english/advisories/2011/0855
http://www.vupen.com/english/advisories/2011/0858
http://www.vupen.com/english/advisories/2011/1010
http://www.vupen.com/english/advisories/2011/1172
https://bugs.webkit.org/show_bug.cgi?id=52688
https://bugzilla.redhat.com/show_bug.cgi?id=692133 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/66506
http://git.gnome.org/browse/xmlsec/commit/?id=2d5eddcc4163ea050cf3a3a1a25452bb5124f780 Patch
http://git.gnome.org/browse/xmlsec/commit/?id=35eaacde6093d6711339754fc2146341b8b9f5fa Patch
http://secunia.com/advisories/43920 Vendor Advisory
http://secunia.com/advisories/44167
http://secunia.com/advisories/44423
http://trac.webkit.org/changeset/79159
http://www.aleksey.com/pipermail/xmlsec/2011/009120.html Patch
http://www.debian.org/security/2011/dsa-2219
http://www.mandriva.com/security/advisories?name=MDVSA-2011:063
http://www.redhat.com/support/errata/RHSA-2011-0486.html
http://www.securityfocus.com/bid/47135
http://www.securitytracker.com/id?1025284
http://www.vupen.com/english/advisories/2011/0855
http://www.vupen.com/english/advisories/2011/0858
http://www.vupen.com/english/advisories/2011/1010
http://www.vupen.com/english/advisories/2011/1172
https://bugs.webkit.org/show_bug.cgi?id=52688
https://bugzilla.redhat.com/show_bug.cgi?id=692133 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/66506
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:aleksey:xml_security_library:*:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.2a:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.4:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.5:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.6:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.7:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.8:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.9:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.10:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.11:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.12:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.13:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.14:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.0.15:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.8:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.9:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.10:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.11:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.13:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.14:*:*:*:*:*:*:*
cpe:2.3:a:aleksey:xml_security_library:1.2.15:*:*:*:*:*:*:*
cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:26

Type Values Removed Values Added
References () http://git.gnome.org/browse/xmlsec/commit/?id=2d5eddcc4163ea050cf3a3a1a25452bb5124f780 - Patch () http://git.gnome.org/browse/xmlsec/commit/?id=2d5eddcc4163ea050cf3a3a1a25452bb5124f780 - Patch
References () http://git.gnome.org/browse/xmlsec/commit/?id=35eaacde6093d6711339754fc2146341b8b9f5fa - Patch () http://git.gnome.org/browse/xmlsec/commit/?id=35eaacde6093d6711339754fc2146341b8b9f5fa - Patch
References () http://secunia.com/advisories/43920 - Vendor Advisory () http://secunia.com/advisories/43920 - Vendor Advisory
References () http://secunia.com/advisories/44167 - () http://secunia.com/advisories/44167 -
References () http://secunia.com/advisories/44423 - () http://secunia.com/advisories/44423 -
References () http://trac.webkit.org/changeset/79159 - () http://trac.webkit.org/changeset/79159 -
References () http://www.aleksey.com/pipermail/xmlsec/2011/009120.html - Patch () http://www.aleksey.com/pipermail/xmlsec/2011/009120.html - Patch
References () http://www.debian.org/security/2011/dsa-2219 - () http://www.debian.org/security/2011/dsa-2219 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2011:063 - () http://www.mandriva.com/security/advisories?name=MDVSA-2011:063 -
References () http://www.redhat.com/support/errata/RHSA-2011-0486.html - () http://www.redhat.com/support/errata/RHSA-2011-0486.html -
References () http://www.securityfocus.com/bid/47135 - () http://www.securityfocus.com/bid/47135 -
References () http://www.securitytracker.com/id?1025284 - () http://www.securitytracker.com/id?1025284 -
References () http://www.vupen.com/english/advisories/2011/0855 - () http://www.vupen.com/english/advisories/2011/0855 -
References () http://www.vupen.com/english/advisories/2011/0858 - () http://www.vupen.com/english/advisories/2011/0858 -
References () http://www.vupen.com/english/advisories/2011/1010 - () http://www.vupen.com/english/advisories/2011/1010 -
References () http://www.vupen.com/english/advisories/2011/1172 - () http://www.vupen.com/english/advisories/2011/1172 -
References () https://bugs.webkit.org/show_bug.cgi?id=52688 - () https://bugs.webkit.org/show_bug.cgi?id=52688 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=692133 - Patch () https://bugzilla.redhat.com/show_bug.cgi?id=692133 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/66506 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/66506 -

Information

Published : 2011-04-04 12:27

Updated : 2024-11-21 01:26


NVD link : CVE-2011-1425

Mitre link : CVE-2011-1425

CVE.ORG link : CVE-2011-1425


JSON object : View

Products Affected

apple

  • webkit

aleksey

  • xml_security_library
CWE
CWE-264

Permissions, Privileges, and Access Controls