First published: Wed Mar 30 2011(Updated: )
Nicolas Grégoire discovered that xmlsec1 can create a file with attacker-specified path name and content when xmlsec1 is used to verify a signature of a specially-crafted XML file specifying XSLT transformation. This may be used to create or overwrite arbitrary file writeable to the user running xmlsec1. This issue was addressed upstream via following commit, which disables XSLT read/write by default: <a href="http://git.gnome.org/browse/xmlsec/commit/?id=35eaacde6093d6711339754fc2146341b8b9f5fa">http://git.gnome.org/browse/xmlsec/commit/?id=35eaacde6093d6711339754fc2146341b8b9f5fa</a> Acknowledgements: Red Hat would like to thank Nicolas Grégoire and Aleksey Sanin for reporting this issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aleksey Xml Security Library | <=1.2.16 | |
Aleksey Xml Security Library | =0.0.3 | |
Aleksey Xml Security Library | =1.2.10 | |
Aleksey Xml Security Library | =0.0.2a | |
Aleksey Xml Security Library | =0.0.5 | |
Aleksey Xml Security Library | =0.0.9 | |
Aleksey Xml Security Library | =1.2.13 | |
Aleksey Xml Security Library | =1.2.9 | |
Aleksey Xml Security Library | =1.2.14 | |
Aleksey Xml Security Library | =1.0.3 | |
Aleksey Xml Security Library | =1.2.8 | |
Aleksey Xml Security Library | =0.0.13 | |
Aleksey Xml Security Library | =0.1.1 | |
Aleksey Xml Security Library | =1.0.2 | |
Aleksey Xml Security Library | =0.0.2 | |
Aleksey Xml Security Library | =1.2.2 | |
Aleksey Xml Security Library | =1.1.1 | |
Aleksey Xml Security Library | =1.0.0-rc1 | |
Aleksey Xml Security Library | =0.0.12 | |
Aleksey Xml Security Library | =0.0.14 | |
Aleksey Xml Security Library | =0.0.10 | |
Aleksey Xml Security Library | =1.2.4 | |
Aleksey Xml Security Library | =1.0.1 | |
Aleksey Xml Security Library | =0.0.7 | |
Aleksey Xml Security Library | =0.0.6 | |
Aleksey Xml Security Library | =1.2.1 | |
Aleksey Xml Security Library | =1.2.7 | |
Aleksey Xml Security Library | =0.0.15 | |
Aleksey Xml Security Library | =1.2.11 | |
Aleksey Xml Security Library | =1.0.4 | |
Aleksey Xml Security Library | =1.2.5 | |
Aleksey Xml Security Library | =1.1.0 | |
Aleksey Xml Security Library | =1.2.3 | |
Aleksey Xml Security Library | =1.1.2 | |
Aleksey Xml Security Library | =1.2.6 | |
Aleksey Xml Security Library | =0.1.0 | |
Aleksey Xml Security Library | =1.2.15 | |
Aleksey Xml Security Library | =1.2.0 | |
Aleksey Xml Security Library | =1.0.0 | |
Aleksey Xml Security Library | =0.0.11 | |
Aleksey Xml Security Library | =0.0.4 | |
Apple Webkit | ||
Aleksey Xml Security Library | =0.0.1 | |
Aleksey Xml Security Library | =0.0.8 | |
redhat/xmlsec1 | <1.2.17 | 1.2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.