CVE-2008-2935

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
01/08/2008
Last modified:
11/10/2018

Description

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xmlsoft:libxslt:1.1.8:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.9:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.10:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.11:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.12:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.13:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.14:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.15:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.16:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.17:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.18:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.19:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.20:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.21:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxslt:1.1.22:*:*:*:*:*:*:*