bugzilla.gnome.orgConfirmation
http://bugzilla.gnome.org/show_bug.cgi?id=527297 CVE-2008-1767
libxslt XSL 1.1.23 - File Processing Buffer Overflow
Record summary
CVE-2008-1767 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBlibxslt XSL 1.1.23 - File Processing Buffer OverflowExploitDB exploitby Anthony de Almeida LopesNot analyzed1 file
References
Showing 12 of 30APPLE-SA-2008-11-13Vendor advisory
http://lists.apple.com/archives/security-announce//2008/Nov/msg00001.html APPLE-SA-2008-07-11Vendor advisory
http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html APPLE-SA-2008-10-09Vendor advisory
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html 30315Third-party advisory
http://secunia.com/advisories/30315 30323Third-party advisory
http://secunia.com/advisories/30323 30393Third-party advisory
http://secunia.com/advisories/30393 30521Third-party advisory
http://secunia.com/advisories/30521 30717Third-party advisory
http://secunia.com/advisories/30717 31074Third-party advisory
http://secunia.com/advisories/31074 31363Third-party advisory
http://secunia.com/advisories/31363 32222Third-party advisory
http://secunia.com/advisories/32222