CVE-2019-11068
10.04.2019, 20:29
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.Enginsight
| Vendor | Product | Version |
|---|---|---|
| xmlsoft | libxslt | 𝑥 ≤ 1.1.33 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| debian | debian_linux | 8.0 |
| oracle | jdk | 8.0 |
| netapp | active_iq_unified_manager | - |
| netapp | active_iq_unified_manager | - |
| netapp | cloud_backup | - |
| netapp | e-series_santricity_management_plug-ins | - |
| netapp | e-series_santricity_os_controller | 11.0 ≤ 𝑥 ≤ 11.70.2 |
| netapp | e-series_santricity_storage_manager | - |
| netapp | e-series_santricity_unified_manager | - |
| netapp | e-series_santricity_web_services_proxy | - |
| netapp | element_software | - |
| netapp | hci_management_node | - |
| netapp | oncommand_insight | - |
| netapp | oncommand_workflow_automation | - |
| netapp | plug-in_for_symantec_netbackup | - |
| netapp | santricity_unified_manager | - |
| netapp | snapmanager | - |
| netapp | snapmanager | - |
| netapp | solidfire | - |
| netapp | steelstore_cloud_integrated_storage | - |
| opensuse | leap | 15.0 |
| opensuse | leap | 15.1 |
| opensuse | leap | 42.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References