CVE-2011-1425

Publication date 4 April 2011

Last updated 24 July 2024


Ubuntu priority

Description

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

Status

Package Ubuntu Release Status
xmlsec1 13.10 saucy
Not affected
13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Fixed 1.2.14-1+squeeze1build0.11.04.1
10.10 maverick
Fixed 1.2.14-1+squeeze1build0.10.10.1
10.04 LTS lucid Ignored end of life
9.10 karmic Ignored end of life
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
xmlsec1

Access our resources on patching vulnerabilities