CVE Vulnerabilities

CVE-2011-1425

Published: Apr 04, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

Affected Software

NameVendorStart VersionEnd Version
Xml_security_libraryAleksey*1.2.16 (including)
Xml_security_libraryAleksey0.0.1 (including)0.0.1 (including)
Xml_security_libraryAleksey0.0.2 (including)0.0.2 (including)
Xml_security_libraryAleksey0.0.2a (including)0.0.2a (including)
Xml_security_libraryAleksey0.0.3 (including)0.0.3 (including)
Xml_security_libraryAleksey0.0.4 (including)0.0.4 (including)
Xml_security_libraryAleksey0.0.5 (including)0.0.5 (including)
Xml_security_libraryAleksey0.0.6 (including)0.0.6 (including)
Xml_security_libraryAleksey0.0.7 (including)0.0.7 (including)
Xml_security_libraryAleksey0.0.8 (including)0.0.8 (including)
Xml_security_libraryAleksey0.0.9 (including)0.0.9 (including)
Xml_security_libraryAleksey0.0.10 (including)0.0.10 (including)
Xml_security_libraryAleksey0.0.11 (including)0.0.11 (including)
Xml_security_libraryAleksey0.0.12 (including)0.0.12 (including)
Xml_security_libraryAleksey0.0.13 (including)0.0.13 (including)
Xml_security_libraryAleksey0.0.14 (including)0.0.14 (including)
Xml_security_libraryAleksey0.0.15 (including)0.0.15 (including)
Xml_security_libraryAleksey0.1.0 (including)0.1.0 (including)
Xml_security_libraryAleksey0.1.1 (including)0.1.1 (including)
Xml_security_libraryAleksey1.0.0 (including)1.0.0 (including)
Xml_security_libraryAleksey1.0.0-rc1 (including)1.0.0-rc1 (including)
Xml_security_libraryAleksey1.0.1 (including)1.0.1 (including)
Xml_security_libraryAleksey1.0.2 (including)1.0.2 (including)
Xml_security_libraryAleksey1.0.3 (including)1.0.3 (including)
Xml_security_libraryAleksey1.0.4 (including)1.0.4 (including)
Xml_security_libraryAleksey1.1.0 (including)1.1.0 (including)
Xml_security_libraryAleksey1.1.1 (including)1.1.1 (including)
Xml_security_libraryAleksey1.1.2 (including)1.1.2 (including)
Xml_security_libraryAleksey1.2.0 (including)1.2.0 (including)
Xml_security_libraryAleksey1.2.1 (including)1.2.1 (including)
Xml_security_libraryAleksey1.2.2 (including)1.2.2 (including)
Xml_security_libraryAleksey1.2.3 (including)1.2.3 (including)
Xml_security_libraryAleksey1.2.4 (including)1.2.4 (including)
Xml_security_libraryAleksey1.2.5 (including)1.2.5 (including)
Xml_security_libraryAleksey1.2.6 (including)1.2.6 (including)
Xml_security_libraryAleksey1.2.7 (including)1.2.7 (including)
Xml_security_libraryAleksey1.2.8 (including)1.2.8 (including)
Xml_security_libraryAleksey1.2.9 (including)1.2.9 (including)
Xml_security_libraryAleksey1.2.10 (including)1.2.10 (including)
Xml_security_libraryAleksey1.2.11 (including)1.2.11 (including)
Xml_security_libraryAleksey1.2.13 (including)1.2.13 (including)
Xml_security_libraryAleksey1.2.14 (including)1.2.14 (including)
Xml_security_libraryAleksey1.2.15 (including)1.2.15 (including)
WebkitApple**
Red Hat Enterprise Linux 4RedHatxmlsec1-0:1.2.6-3.2*
Red Hat Enterprise Linux 5RedHatxmlsec1-0:1.2.9-8.1.2*
Xmlsec1Ubuntudapper*
Xmlsec1Ubuntuhardy*
Xmlsec1Ubuntukarmic*
Xmlsec1Ubuntulucid*
Xmlsec1Ubuntumaverick*
Xmlsec1Ubuntunatty*
Xmlsec1Ubuntuupstream*

References