Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-1425
Description:xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.
Test IDs: 1.3.6.1.4.1.25623.1.0.880504   1.3.6.1.4.1.25623.1.0.881415   1.3.6.1.4.1.25623.1.0.69399   1.3.6.1.4.1.25623.1.0.881431   1.3.6.1.4.1.25623.1.0.831362   1.3.6.1.4.1.25623.1.0.69563   1.3.6.1.4.1.25623.1.0.69637   1.3.6.1.4.1.25623.1.0.880537   1.3.6.1.4.1.25623.1.0.870429   1.3.6.1.4.1.25623.1.0.69445  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-1425
BugTraq ID: 47135
http://www.securityfocus.com/bid/47135
Debian Security Information: DSA-2219 (Google Search)
http://www.debian.org/security/2011/dsa-2219
http://www.mandriva.com/security/advisories?name=MDVSA-2011:063
http://www.aleksey.com/pipermail/xmlsec/2011/009120.html
RedHat Security Advisories: RHSA-2011:0486
http://www.redhat.com/support/errata/RHSA-2011-0486.html
http://www.securitytracker.com/id?1025284
http://secunia.com/advisories/43920
http://secunia.com/advisories/44167
http://secunia.com/advisories/44423
http://www.vupen.com/english/advisories/2011/0855
http://www.vupen.com/english/advisories/2011/0858
http://www.vupen.com/english/advisories/2011/1010
http://www.vupen.com/english/advisories/2011/1172
XForce ISS Database: xmlsecurity-xmlfiles-sec-bypass(66506)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66506




© 1998-2025 E-Soft Inc. All rights reserved.