CVE-2019-11068

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
xmlsoftlibxslt
𝑥
≤ 1.1.33
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
18.10
debiandebian_linux
8.0
oraclejdk
8.0
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappcloud_backup
-
netappe-series_santricity_management_plug-ins
-
netappe-series_santricity_os_controller
11.0 ≤
𝑥
≤ 11.70.2
netappe-series_santricity_storage_manager
-
netappe-series_santricity_unified_manager
-
netappe-series_santricity_web_services_proxy
-
netappelement_software
-
netapphci_management_node
-
netapponcommand_insight
-
netapponcommand_workflow_automation
-
netappplug-in_for_symantec_netbackup
-
netappsantricity_unified_manager
-
netappsnapmanager
-
netappsnapmanager
-
netappsolidfire
-
netappsteelstore_cloud_integrated_storage
-
opensuseleap
15.0
opensuseleap
15.1
opensuseleap
42.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxslt
bullseye (security)
1.1.34-4+deb11u1
fixed
bullseye
1.1.34-4+deb11u1
fixed
bookworm
1.1.35-1
fixed
sid
1.1.35-1.1
fixed
trixie
1.1.35-1.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxslt
cosmic
Fixed 1.1.32-2ubuntu0.1
released
bionic
Fixed 1.1.29-5ubuntu0.1
released
xenial
Fixed 1.1.28-2.1ubuntu0.2
released
trusty
Fixed 1.1.28-2ubuntu0.2
released
References