CVE Database
/

CVE-2008-2935

Back to search

CVE-2008-2935

Published: Aug 1, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2008:0649
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:10827
vdb-entry
signature
x_refsource_OVAL
libxslt-multiple-crypto-bo(44141)
vdb-entry
x_refsource_XF
32453
third-party-advisory
x_refsource_SECUNIA
31399
third-party-advisory
x_refsource_SECUNIA
31363
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-7029
vendor-advisory
x_refsource_FEDORA
30467
vdb-entry
x_refsource_BID
4078
third-party-advisory
x_refsource_SREASON
GLSA-200808-06
vendor-advisory
x_refsource_GENTOO
31310
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:160
vendor-advisory
x_refsource_MANDRIVA
USN-633-1
vendor-advisory
x_refsource_UBUNTU
31331
third-party-advisory
x_refsource_SECUNIA
20081027 rPSA-2008-0306-1 libxslt
mailing-list
x_refsource_BUGTRAQ
20080801 libxslt heap overflow
mailing-list
x_refsource_BUGTRAQ
31230
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-7062
vendor-advisory
x_refsource_FEDORA
ADV-2008-2266
vdb-entry
x_refsource_VUPEN
1020596
vdb-entry
x_refsource_SECTRACK
DSA-1624
vendor-advisory
x_refsource_DEBIAN
31395
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now