MEDIUM · 5.1

CVE-2011-1425

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involv...

Vulnerability Description

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

CVSS Score

5.1

MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AlekseyXml Security Library<= 1.2.16
AppleWebkitAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-1425?

CVE-2011-1425 is a vulnerability with a CVSS score of 5.1 (MEDIUM). xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involv...

How severe is CVE-2011-1425?

CVE-2011-1425 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-1425?

Check the references section above for vendor advisories and patch information. Affected products include: Aleksey Xml Security Library, Apple Webkit.