Improper Input Validation Affecting libxslt package, versions <1.1.26-13
Snyk CVSS
Attack Complexity
Low
Threat Intelligence
EPSS
1.45% (87th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN9-LIBXSLT-308034
- published 27 Jun 2012
- disclosed 27 Jun 2012
Introduced: 27 Jun 2012
CVE-2012-2825 Open this link in a new tabHow to fix?
Upgrade Debian:9
libxslt
to version 1.1.26-13 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream libxslt
package and not the libxslt
package as distributed by Debian
.
See How to fix?
for Debian:9
relevant fixed versions and status.
The XSL implementation in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.
References
- http://support.apple.com/kb/HT5934
- http://support.apple.com/kb/HT6001
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00009.html
- http://lists.apple.com/archives/security-announce/2013/Sep/msg00006.html
- http://googlechromereleases.blogspot.com/2012/06/stable-channel-update_26.html
- http://code.google.com/p/chromium/issues/detail?id=127417
- https://security-tracker.debian.org/tracker/CVE-2012-2825
- https://hermes.opensuse.org/messages/15075728
- https://www.suse.com/support/update/announcement/2013/suse-su-20131654-1.html
- https://www.suse.com/support/update/announcement/2013/suse-su-20131656-1.html
- http://secunia.com/advisories/54886
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2012-2825