libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libxslt | Xmlsoft | * | 1.1.33 (including) |
Red Hat Enterprise Linux 7 | RedHat | libxslt-0:1.1.28-6.el7 | * |
Red Hat Enterprise Linux 8 | RedHat | libxslt-0:1.1.32-5.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | libxslt-0:1.1.32-5.el8 | * |
Libxslt | Ubuntu | bionic | * |
Libxslt | Ubuntu | cosmic | * |
Libxslt | Ubuntu | devel | * |
Libxslt | Ubuntu | trusty | * |
Libxslt | Ubuntu | xenial | * |