CVE-2019-11068
10.04.2019, 20:29
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.Enginsight
Vendor | Product | Version |
---|---|---|
xmlsoft | libxslt | 𝑥 ≤ 1.1.33 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
debian | debian_linux | 8.0 |
oracle | jdk | 8.0 |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | cloud_backup | - |
netapp | e-series_santricity_management_plug-ins | - |
netapp | e-series_santricity_os_controller | 11.0 ≤ 𝑥 ≤ 11.70.2 |
netapp | e-series_santricity_storage_manager | - |
netapp | e-series_santricity_unified_manager | - |
netapp | e-series_santricity_web_services_proxy | - |
netapp | element_software | - |
netapp | hci_management_node | - |
netapp | oncommand_insight | - |
netapp | oncommand_workflow_automation | - |
netapp | plug-in_for_symantec_netbackup | - |
netapp | santricity_unified_manager | - |
netapp | snapmanager | - |
netapp | snapmanager | - |
netapp | solidfire | - |
netapp | steelstore_cloud_integrated_storage | - |
opensuse | leap | 15.0 |
opensuse | leap | 15.1 |
opensuse | leap | 42.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References