CVE-2008-2935

Impact:
Important
Public Date:
2008-07-31
Bugzilla:
455848: CVE-2008-2935 libxslt: buffer overflow in libexslt RC4 encryption/decryption functions

The MITRE CVE dictionary describes this issue as:

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

Find out more about CVE-2008-2935 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 4 (libxslt) RHSA-2008:0649 2008-07-31
Red Hat Enterprise Linux 5 (libxslt) RHSA-2008:0649 2008-07-31

Acknowledgements

Red Hat would like to thank Chris Evans and oCERT for reporting this vulnerability.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.