CVE-2008-1767
libxslt XSL 1.1.23 - File Processing Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.
Vulnerabilidad de desbordamiento de búfer en pattern.c en libxslt anteriores a 1.1.24, permiten a atacantes, dependiendo del contexto, provocar una denegación de servicio (caída) y posiblemente ejecutar código arbitrario a través de un fichero de hoja de estilo XSL con una condición "transformation match" XSLT larga que dispara un número grande de pasos.
It was discovered that long transformation matches in libxslt could overflow. If an attacker were able to make an application linked against libxslt process malicious XSL style sheet input, they could execute arbitrary code with user privileges or cause the application to crash, leading to a denial of service. Chris Evans discovered that the RC4 processing code in libxslt did not correctly handle corrupted key information. If a remote attacker were able to make an application linked against libxslt process malicious XML input, they could crash the application, leading to a denial of service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-04-12 CVE Reserved
- 2008-05-21 First Exploit
- 2008-05-23 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (32)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/30393 | Third Party Advisory | |
http://secunia.com/advisories/30521 | Third Party Advisory | |
http://secunia.com/advisories/30717 | Third Party Advisory | |
http://secunia.com/advisories/31074 | Third Party Advisory | |
http://secunia.com/advisories/31363 | Third Party Advisory | |
http://secunia.com/advisories/32222 | Third Party Advisory | |
http://secunia.com/advisories/32706 | Third Party Advisory | |
http://support.apple.com/kb/HT3216 | X_refsource_confirm |
|
http://support.apple.com/kb/HT3298 | X_refsource_confirm |
|
http://www.securityfocus.com/bid/31681 | Vdb Entry | |
http://www.securitytracker.com/id?1020071 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1580/references | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2094/references | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2780 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42560 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9785 | Signature |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31815 | 2008-05-21 | |
http://bugzilla.gnome.org/show_bug.cgi?id=527297 | 2024-08-07 | |
http://www.securityfocus.com/bid/29312 | 2024-08-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Desktop Search vendor "Redhat" for product "Desktop" | 3 Search vendor "Redhat" for product "Desktop" and version "3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | as |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | es |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 2.1 Search vendor "Redhat" for product "Enterprise Linux" and version "2.1" | ws |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 4.0 Search vendor "Redhat" for product "Enterprise Linux" and version "4.0" | as |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 4.0 Search vendor "Redhat" for product "Enterprise Linux" and version "4.0" | es |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 4.0 Search vendor "Redhat" for product "Enterprise Linux" and version "4.0" | ws |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 5.0 Search vendor "Redhat" for product "Enterprise Linux" and version "5.0" | server |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 4 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 5 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "5" | client |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Workstation Search vendor "Redhat" for product "Enterprise Linux Desktop Workstation" | 5 Search vendor "Redhat" for product "Enterprise Linux Desktop Workstation" and version "5" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Linux Advanced Workstation Search vendor "Redhat" for product "Linux Advanced Workstation" | 2.1 Search vendor "Redhat" for product "Linux Advanced Workstation" and version "2.1" | itanium |
Affected
|