REDHAT-BUG-684386: Low severity libxslt vulnerability
Chris Evans discovered a heap address leak in XSLT The bug is in the generate-id() XPath function, and is sometimes used in XSL transforms. This is a low severity information leak, that does not corrupt anything, However it can be paired with other bugs and can be perhaps used as an exploit aid against ASLR.
References: http://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.html http://git.gnome.org/browse/libxslt/commit/?id=ecb6bcb8d1b7e44842edde3929f412d46b40c89f
This has been assigned CVE-2011-1202.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-684386?
The severity of REDHAT-BUG-684386 is low, involving an information leak without corruption.
How does REDHAT-BUG-684386 impact security?
REDHAT-BUG-684386 may be used in conjunction with other vulnerabilities to aid exploit attempts.
What software is affected by REDHAT-BUG-684386?
The affected software for REDHAT-BUG-684386 includes GNOME libxslt.
Is there a fix for REDHAT-BUG-684386?
Yes, users should update their GNOME libxslt to the latest version to mitigate the issue.
What function is involved in REDHAT-BUG-684386?
The function involved in REDHAT-BUG-684386 is the generate-id() XPath function used in XSL transforms.