CVE
- Id
- 49337
- CVE No.
- CVE-2011-1425
- Status
- Candidate
- Description
- xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.
- Phase
- Assigned (20110314)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
535694 | 49337 | CVE-2011-1425 | MLIST:[xmlsec] 20110331 New xmlsec 1.2.17 release | View |
535695 | 49337 | CVE-2011-1425 | URL:http://www.aleksey.com/pipermail/xmlsec/2011/009120.html | View |
535696 | 49337 | CVE-2011-1425 | CONFIRM:http://git.gnome.org/browse/xmlsec/commit/?id=2d5eddcc4163ea050cf3a3a1a25452bb5124f780 | View |
535697 | 49337 | CVE-2011-1425 | CONFIRM:http://git.gnome.org/browse/xmlsec/commit/?id=35eaacde6093d6711339754fc2146341b8b9f5fa | View |
535698 | 49337 | CVE-2011-1425 | CONFIRM:http://trac.webkit.org/changeset/79159 | View |
535699 | 49337 | CVE-2011-1425 | CONFIRM:https://bugs.webkit.org/show_bug.cgi?id=52688 | View |
535700 | 49337 | CVE-2011-1425 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=692133 | View |
535701 | 49337 | CVE-2011-1425 | DEBIAN:DSA-2219 | View |
535702 | 49337 | CVE-2011-1425 | URL:http://www.debian.org/security/2011/dsa-2219 | View |
535703 | 49337 | CVE-2011-1425 | MANDRIVA:MDVSA-2011:063 | View |
535704 | 49337 | CVE-2011-1425 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2011:063 | View |
535705 | 49337 | CVE-2011-1425 | REDHAT:RHSA-2011:0486 | View |
535706 | 49337 | CVE-2011-1425 | URL:http://www.redhat.com/support/errata/RHSA-2011-0486.html | View |
535707 | 49337 | CVE-2011-1425 | BID:47135 | View |
535708 | 49337 | CVE-2011-1425 | URL:http://www.securityfocus.com/bid/47135 | View |
535709 | 49337 | CVE-2011-1425 | SECTRACK:1025284 | View |
535710 | 49337 | CVE-2011-1425 | URL:http://www.securitytracker.com/id?1025284 | View |
535711 | 49337 | CVE-2011-1425 | SECUNIA:43920 | View |
535712 | 49337 | CVE-2011-1425 | URL:http://secunia.com/advisories/43920 | View |
535713 | 49337 | CVE-2011-1425 | SECUNIA:44167 | View |
535714 | 49337 | CVE-2011-1425 | URL:http://secunia.com/advisories/44167 | View |
535715 | 49337 | CVE-2011-1425 | SECUNIA:44423 | View |
535716 | 49337 | CVE-2011-1425 | URL:http://secunia.com/advisories/44423 | View |
535717 | 49337 | CVE-2011-1425 | VUPEN:ADV-2011-1010 | View |
535718 | 49337 | CVE-2011-1425 | URL:http://www.vupen.com/english/advisories/2011/1010 | View |
535719 | 49337 | CVE-2011-1425 | VUPEN:ADV-2011-1172 | View |
535720 | 49337 | CVE-2011-1425 | URL:http://www.vupen.com/english/advisories/2011/1172 | View |
535721 | 49337 | CVE-2011-1425 | VUPEN:ADV-2011-0855 | View |
535722 | 49337 | CVE-2011-1425 | URL:http://www.vupen.com/english/advisories/2011/0855 | View |
535723 | 49337 | CVE-2011-1425 | VUPEN:ADV-2011-0858 | View |
535724 | 49337 | CVE-2011-1425 | URL:http://www.vupen.com/english/advisories/2011/0858 | View |
535725 | 49337 | CVE-2011-1425 | XF:xmlsecurity-xmlfiles-sec-bypass(66506) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
34151 | JVNDB-2011-004393 | Ipswitch IMail のSTARTTLS 実装における暗号化された SMTP セッションにコマンドを挿入される脆弱性 | Ipswitch IMail のサーバの STARTTLS 実装は、I/O バッファリングを適切に制限しないため、暗号化された SMTP セッションにコマンドを挿入される脆弱性が存在します。 | CVE-2011-1430 | 49337 | 6.8 | http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-004393.html | View |