CRITICAL · 9.8

CVE-2019-11068

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a ...

Vulnerability Description

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
XmlsoftLibxslt<= 1.1.33
CanonicalUbuntu Linux12.04
DebianDebian Linux8.0
FedoraprojectFedora29
OracleJdk8.0
NetappActive Iq Unified Manager-
NetappCloud Backup-
NetappE-Series Santricity Management Plug-Ins-
NetappE-Series Santricity Os Controller>= 11.0, <= 11.70.2
NetappE-Series Santricity Storage Manager-
NetappE-Series Santricity Unified Manager-
NetappE-Series Santricity Web Services Proxy-
NetappElement Software-
NetappHci Management Node-
NetappOncommand Insight-
NetappOncommand Workflow Automation-
NetappPlug-In For Symantec Netbackup-
NetappSantricity Unified Manager-
NetappSnapmanager-
NetappSolidfire-

References

FAQ

What is CVE-2019-11068?

CVE-2019-11068 is a vulnerability with a CVSS score of 9.8 (CRITICAL). libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a ...

How severe is CVE-2019-11068?

CVE-2019-11068 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-11068?

Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxslt, Canonical Ubuntu Linux, Debian Debian Linux, Fedoraproject Fedora, Oracle Jdk.