*** This bug is a security vulnerability ***

Public security bug reported:

CVE-2008-1767 description:

"It was discovered that libxslt, an XSLT processing runtime library,
could be coerced into executing arbitrary code via a buffer overflow
when an XSL style sheet file with a long XSLT "transformation match"
condition triggered a large number of steps."

http://www.debian.org/security/2008/dsa-1589
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1767
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1767

** Affects: libxslt (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: libxslt (Debian)
     Importance: Unknown
         Status: Fix Released

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-1767

** Bug watch added: Debian Bug tracker #482664
   http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482664

** Also affects: libxslt (Debian) via
   http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482664
   Importance: Unknown
       Status: Unknown

-- 
[CVE-2008-1767] Buffer overflow in libxslt
https://bugs.launchpad.net/bugs/235909
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to