RHSA-2012:1265: Important: libxslt security update

Published Sep 13, 2012
·
Updated

libxslt is a library for transforming XML files into other textual formats(including HTML, plain text, and other XML representations of theunderlying data) using the standard XSLT stylesheet transformationmechanism.A heap-based buffer overflow flaw was found in the way libxslt appliedtemplates to nodes selected by certain namespaces. An attacker could usethis flaw to create a malicious XSL file that, when used by an applicationlinked against libxslt to perform an XSL transformation, could cause theapplication to crash or, possibly, execute arbitrary code with theprivileges of the user running the application. (CVE-2012-2871)Several denial of service flaws were found in libxslt. An attacker coulduse these flaws to create a malicious XSL file that, when used by anapplication linked against libxslt to perform an XSL transformation, couldcause the application to crash. (CVE-2012-2825, CVE-2012-2870,CVE-2011-3970)An information leak could occur if an application using libxslt processedan untrusted XPath expression, or used a malicious XSL file to perform anXSL transformation. If combined with other flaws, this leak could possiblyhelp an attacker bypass intended memory corruption protections.(CVE-2011-1202)All libxslt users are advised to upgrade to these updated packages, whichcontain backported patches to resolve these issues. All runningapplications linked against libxslt must be restarted for this update totake effect.

Affected Software

16 affected componentsFixes available
redhat/libxslt<1.1.26-2.el6_3.1
1.1.26-2.el6_3.1
redhat/libxslt<1.1.26-2.el6_3.1
1.1.26-2.el6_3.1
redhat/libxslt-debuginfo<1.1.26-2.el6_3.1
1.1.26-2.el6_3.1
redhat/libxslt-debuginfo<1.1.26-2.el6_3.1
1.1.26-2.el6_3.1
redhat/libxslt-devel<1.1.26-2.el6_3.1
1.1.26-2.el6_3.1
redhat/libxslt-devel<1.1.26-2.el6_3.1
1.1.26-2.el6_3.1
redhat/libxslt-python<1.1.26-2.el6_3.1
1.1.26-2.el6_3.1
redhat/libxslt-python<1.1.26-2.el6_3.1
1.1.26-2.el6_3.1
redhat/libxslt<1.1.17-4.el5_8.3
1.1.17-4.el5_8.3
redhat/libxslt<1.1.17-4.el5_8.3
1.1.17-4.el5_8.3
redhat/libxslt-debuginfo<1.1.17-4.el5_8.3
1.1.17-4.el5_8.3
redhat/libxslt-debuginfo<1.1.17-4.el5_8.3
1.1.17-4.el5_8.3
redhat/libxslt-devel<1.1.17-4.el5_8.3
1.1.17-4.el5_8.3
redhat/libxslt-devel<1.1.17-4.el5_8.3
1.1.17-4.el5_8.3
redhat/libxslt-python<1.1.17-4.el5_8.3
1.1.17-4.el5_8.3
redhat/libxslt-python<1.1.17-4.el5_8.3
1.1.17-4.el5_8.3

Remediation

Event History

Sep 13, 2012
Advisory Published
12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2012:1265?

RHSA-2012:1265 is classified as a moderate security vulnerability due to the potential for heap-based buffer overflow.

2

How do I fix RHSA-2012:1265?

To fix RHSA-2012:1265, update the libxslt package to version 1.1.26-2.el6_3.1 or later.

3

What systems are affected by RHSA-2012:1265?

The affected systems include various versions of the libxslt package in Red Hat Enterprise Linux 5 and 6.

4

What are the consequences of exploiting RHSA-2012:1265?

Exploiting RHSA-2012:1265 could allow an attacker to execute arbitrary code on the affected system.

5

Is there a workaround for RHSA-2012:1265?

There are no specific workarounds for RHSA-2012:1265; the recommended action is to apply the security update.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203