Vulnerability Description
Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Desktop | 3 |
| Redhat | Enterprise Linux | 2.1 |
| Redhat | Enterprise Linux Desktop | 4 |
| Redhat | Enterprise Linux Desktop Workstation | 5 |
| Redhat | Linux Advanced Workstation | 2.1 |
Related Weaknesses (CWE)
References
- http://bugzilla.gnome.org/show_bug.cgi?id=527297Exploit
- http://lists.apple.com/archives/security-announce//2008/Nov/msg00001.html
- http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
- http://secunia.com/advisories/30315Vendor Advisory
- http://secunia.com/advisories/30323Vendor Advisory
- http://secunia.com/advisories/30393
- http://secunia.com/advisories/30521
- http://secunia.com/advisories/30717
- http://secunia.com/advisories/31074
- http://secunia.com/advisories/31363
- http://secunia.com/advisories/32222
- http://secunia.com/advisories/32706
- http://security.gentoo.org/glsa/glsa-200806-02.xml
- http://support.apple.com/kb/HT3216
FAQ
What is CVE-2008-1767?
CVE-2008-1767 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a lon...
How severe is CVE-2008-1767?
CVE-2008-1767 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1767?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Desktop, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Desktop Workstation, Redhat Linux Advanced Workstation.