[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2011:063 -- Mandriva xmlsec1

ID: oval:org.secpod.oval:def:300435Date: (C)2012-01-07   (M)2021-09-11
Class: PATCHFamily: unix




A vulnerability was discovered and corrected in xmlsec1: xslt.c in XML Security Library before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification . Packages for 2009.0 are provided as of the Extended Maintenance Program

Platform:
Mandriva Linux 2010.0
Mandriva Linux 2009.0
Product:
xmlsec1
Reference:
MDVSA-2011:063
CVE-2011-1425
CVE    1
CVE-2011-1425
CPE    2
cpe:/o:mandriva:linux:2009.0
cpe:/o:mandriva:linux:2010.0

© SecPod Technologies