CVE-2008-2935
libxslt - arbitrary code execution
EPSS 12.8%
描述
Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."
如何修補 CVE-2008-2935
要修補 CVE-2008-2935,請將受影響套件升級到下列已修補版本。
- Debian/libxslt—升級至 1.1.24-2 或更新版本
- Debian/libxslt—升級至 1.1.19-3 或更新版本
- —升級至 1.1.24-1+lenny1 或更新版本
CVE-2008-2935 正在被利用嗎?
中等 — EPSS 為 12.8%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 1.1.24-2
- from 0, < 1.1.19-3
- from 0, < 1.1.24-1+lenny1