Description
Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1624-1 | New libxslt packages fix arbitrary code execution |
Ubuntu USN |
USN-633-1 | libxslt vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T09:21:34.339Z
Reserved: 2008-06-30T00:00:00.000Z
Link: CVE-2008-2935
No data.
Status : Modified
Published: 2008-08-01T14:41:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-2935
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN