CVE-2012-2870
libxslt - several
EPSS 2.5%
描述
libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.
如何修補 CVE-2012-2870
要修補 CVE-2012-2870,請將受影響套件升級到下列已修補版本。
- Debian/libxslt—升級至 1.1.26-14 或更新版本
- Debian/libxslt—升級至 1.1.26-6+squeeze2 或更新版本
CVE-2012-2870 正在被利用嗎?
低 — EPSS 為 2.5%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1.1.26-14
- from 0, < 1.1.26-6+squeeze2