Description
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Published: 2019-04-10
Score: 9.8 Critical
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-1756-1 libxslt security update
EUVD EUVD EUVD-2022-5058 libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Github GHSA Github GHSA GHSA-qxcg-xjjg-66mj Nokogiri vulnerable to libxslt protection mechanism bypass
Ubuntu USN Ubuntu USN USN-3947-1 Libxslt vulnerability
Ubuntu USN Ubuntu USN USN-3947-2 Libxslt vulnerability
History

No history.

Subscriptions

Canonical Ubuntu Linux
Debian Debian Linux
Fedoraproject Fedora
Netapp Active Iq Unified Manager Cloud Backup E-series Santricity Management Plug-ins E-series Santricity Os Controller E-series Santricity Storage Manager E-series Santricity Unified Manager E-series Santricity Web Services Proxy Element Software Hci Management Node Oncommand Insight Oncommand Workflow Automation Plug-in For Symantec Netbackup Santricity Unified Manager Snapmanager Solidfire Steelstore Cloud Integrated Storage
Opensuse Leap
Oracle Jdk
Redhat Enterprise Linux
Xmlsoft Libxslt
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T22:40:16.229Z

Reserved: 2019-04-10T00:00:00.000Z

Link: CVE-2019-11068

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-10T20:29:01.147

Modified: 2024-11-21T04:20:28.480

Link: CVE-2019-11068

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-04-10T00:00:00Z

Links: CVE-2019-11068 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses