Back to search
CVE-2008-2935
Published: Aug 1, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2008:0649
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:10827
vdb-entry
signature
x_refsource_OVAL
libxslt-multiple-crypto-bo(44141)
vdb-entry
x_refsource_XF
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0306
x_refsource_CONFIRM
32453
third-party-advisory
x_refsource_SECUNIA
31399
third-party-advisory
x_refsource_SECUNIA
31363
third-party-advisory
x_refsource_SECUNIA
http://www.scary.beasts.org/security/CESA-2008-003.html
x_refsource_MISC
FEDORA-2008-7029
vendor-advisory
x_refsource_FEDORA
20080731 [oCERT-2008-009] libxslt heap overflow
mailing-list
x_refsource_BUGTRAQ
30467
vdb-entry
x_refsource_BID
http://www.ocert.org/patches/exslt_crypt.patch
x_refsource_MISC
4078
third-party-advisory
x_refsource_SREASON
GLSA-200808-06
vendor-advisory
x_refsource_GENTOO
31310
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:160
vendor-advisory
x_refsource_MANDRIVA
USN-633-1
vendor-advisory
x_refsource_UBUNTU
31331
third-party-advisory
x_refsource_SECUNIA
20081027 rPSA-2008-0306-1 libxslt
mailing-list
x_refsource_BUGTRAQ
20080801 libxslt heap overflow
mailing-list
x_refsource_BUGTRAQ
31230
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-7062
vendor-advisory
x_refsource_FEDORA
ADV-2008-2266
vdb-entry
x_refsource_VUPEN
1020596
vdb-entry
x_refsource_SECTRACK
DSA-1624
vendor-advisory
x_refsource_DEBIAN
31395
third-party-advisory
x_refsource_SECUNIA
http://www.ocert.org/advisories/ocert-2008-009.html
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now