CVE-2019-11068

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
xmlsoftlibxslt
𝑥
≤ 1.1.33
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
18.10
debiandebian_linux
8.0
oraclejdk
8.0
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappcloud_backup
-
netappe-series_santricity_management_plug-ins
-
netappe-series_santricity_os_controller
11.0 ≤
𝑥
≤ 11.70.2
netappe-series_santricity_storage_manager
-
netappe-series_santricity_unified_manager
-
netappe-series_santricity_web_services_proxy
-
netappelement_software
-
netapphci_management_node
-
netapponcommand_insight
-
netapponcommand_workflow_automation
-
netappplug-in_for_symantec_netbackup
-
netappsantricity_unified_manager
-
netappsnapmanager
-
netappsnapmanager
-
netappsolidfire
-
netappsteelstore_cloud_integrated_storage
-
opensuseleap
15.0
opensuseleap
15.1
opensuseleap
42.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxslt
bookworm
1.1.35-1
fixed
bullseye
1.1.34-4+deb11u1
fixed
bullseye (security)
1.1.34-4+deb11u1
fixed
sid
1.1.35-1.1
fixed
trixie
1.1.35-1.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxslt
bionic
Fixed 1.1.29-5ubuntu0.1
released
cosmic
Fixed 1.1.32-2ubuntu0.1
released
trusty
Fixed 1.1.28-2ubuntu0.2
released
xenial
Fixed 1.1.28-2.1ubuntu0.2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libxslt-devel
suse enterprise desktop 15
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP1
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP2
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP3
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP4
1.1.34-150400.1.7
fixed
suse enterprise desktop 15 SP5
1.1.34-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
1.1.34-150400.3.3.1
fixed
suse enterprise desktop 15 SP7
1.1.34-150400.3.6.1
fixed
suse enterprise sap 15
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP1
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP2
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP3
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP4
1.1.34-150400.1.7
fixed
suse enterprise sap 15 SP5
1.1.34-150400.3.3.1
fixed
suse enterprise sap 15 SP6
1.1.34-150400.3.3.1
fixed
suse enterprise sap 15 SP7
1.1.34-150400.3.6.1
fixed
suse enterprise server 15
1.1.32-3.3.1
fixed
suse enterprise server 15 SP1
1.1.32-3.3.1
fixed
suse enterprise server 15 SP2
1.1.32-3.3.1
fixed
suse enterprise server 15 SP3
1.1.32-3.3.1
fixed
suse enterprise server 15 SP4
1.1.34-150400.1.7
fixed
suse enterprise server 15 SP5
1.1.34-150400.3.3.1
fixed
suse enterprise server 15 SP6
1.1.34-150400.3.3.1
fixed
suse enterprise server 15 SP7
1.1.34-150400.3.6.1
fixed
libxslt-tools
suse enterprise desktop 15
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP1
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP2
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP3
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP4
1.1.34-150400.1.7
fixed
suse enterprise desktop 15 SP5
1.1.34-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
1.1.34-150400.3.3.1
fixed
suse enterprise desktop 15 SP7
1.1.34-150400.3.6.1
fixed
suse enterprise sap 12 SP3
1.1.28-17.3.1
fixed
suse enterprise sap 12 SP4
1.1.28-17.3.1
fixed
suse enterprise sap 12 SP5
1.1.28-17.6.1
fixed
suse enterprise sap 15
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP1
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP2
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP3
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP4
1.1.34-150400.1.7
fixed
suse enterprise sap 15 SP5
1.1.34-150400.3.3.1
fixed
suse enterprise sap 15 SP6
1.1.34-150400.3.3.1
fixed
suse enterprise sap 15 SP7
1.1.34-150400.3.6.1
fixed
suse enterprise server 12 SP3
1.1.28-17.3.1
fixed
suse enterprise server 12 SP4
1.1.28-17.3.1
fixed
suse enterprise server 12 SP5
1.1.28-17.6.1
fixed
suse enterprise server 15
1.1.32-3.3.1
fixed
suse enterprise server 15 SP1
1.1.32-3.3.1
fixed
suse enterprise server 15 SP2
1.1.32-3.3.1
fixed
suse enterprise server 15 SP3
1.1.32-3.3.1
fixed
suse enterprise server 15 SP4
1.1.34-150400.1.7
fixed
suse enterprise server 15 SP5
1.1.34-150400.3.3.1
fixed
suse enterprise server 15 SP6
1.1.34-150400.3.3.1
fixed
suse enterprise server 15 SP7
1.1.34-150400.3.6.1
fixed
libxslt1
suse enterprise desktop 15
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP1
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP2
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP3
1.1.32-3.3.1
fixed
suse enterprise desktop 15 SP4
1.1.34-150400.1.7
fixed
suse enterprise desktop 15 SP5
1.1.34-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
1.1.34-150400.3.3.1
fixed
suse enterprise desktop 15 SP7
1.1.34-150400.3.6.1
fixed
suse enterprise sap 12 SP3
1.1.28-17.3.1
fixed
suse enterprise sap 12 SP4
1.1.28-17.3.1
fixed
suse enterprise sap 12 SP5
1.1.28-17.6.1
fixed
suse enterprise sap 15
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP1
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP2
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP3
1.1.32-3.3.1
fixed
suse enterprise sap 15 SP4
1.1.34-150400.1.7
fixed
suse enterprise sap 15 SP5
1.1.34-150400.3.3.1
fixed
suse enterprise sap 15 SP6
1.1.34-150400.3.3.1
fixed
suse enterprise sap 15 SP7
1.1.34-150400.3.6.1
fixed
suse enterprise server 12 SP3
1.1.28-17.3.1
fixed
suse enterprise server 12 SP4
1.1.28-17.3.1
fixed
suse enterprise server 12 SP5
1.1.28-17.6.1
fixed
suse enterprise server 15
1.1.32-3.3.1
fixed
suse enterprise server 15 SP1
1.1.32-3.3.1
fixed
suse enterprise server 15 SP2
1.1.32-3.3.1
fixed
suse enterprise server 15 SP3
1.1.32-3.3.1
fixed
suse enterprise server 15 SP4
1.1.34-150400.1.7
fixed
suse enterprise server 15 SP5
1.1.34-150400.3.3.1
fixed
suse enterprise server 15 SP6
1.1.34-150400.3.3.1
fixed
suse enterprise server 15 SP7
1.1.34-150400.3.6.1
fixed
libxslt1-32bit
suse enterprise sap 12 SP3
1.1.28-17.3.1
fixed
suse enterprise sap 12 SP4
1.1.28-17.3.1
fixed
suse enterprise sap 12 SP5
1.1.28-17.6.1
fixed
suse enterprise server 12 SP3
1.1.28-17.3.1
fixed
suse enterprise server 12 SP4
1.1.28-17.3.1
fixed
suse enterprise server 12 SP5
1.1.28-17.6.1
fixed
rmt-server
suse enterprise sap 15 SP1
2.3.1-3.3.3
fixed
suse enterprise sap 15 SP2
2.5.4-1.39
fixed
suse enterprise sap 15 SP3
2.6.8-1.2
fixed
suse enterprise sap 15 SP4
2.7.1-150400.1.7
fixed
suse enterprise sap 15 SP7
2.21-150700.1.21
fixed
suse enterprise server 15 SP1
2.3.1-3.3.3
fixed
suse enterprise server 15 SP2
2.5.4-1.39
fixed
suse enterprise server 15 SP3
2.6.8-1.2
fixed
suse enterprise server 15 SP4
2.7.1-150400.1.7
fixed
suse enterprise server 15 SP7
2.21-150700.1.21
fixed
rmt-server-config
suse enterprise sap 15 SP1
2.3.1-3.3.3
fixed
suse enterprise sap 15 SP2
2.5.4-1.39
fixed
suse enterprise sap 15 SP3
2.6.8-1.2
fixed
suse enterprise sap 15 SP4
2.7.1-150400.1.7
fixed
suse enterprise sap 15 SP7
2.21-150700.1.21
fixed
suse enterprise server 15 SP1
2.3.1-3.3.3
fixed
suse enterprise server 15 SP2
2.5.4-1.39
fixed
suse enterprise server 15 SP3
2.6.8-1.2
fixed
suse enterprise server 15 SP4
2.7.1-150400.1.7
fixed
suse enterprise server 15 SP7
2.21-150700.1.21
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libxslt
RHEL 7
0:1.1.28-6.el7
fixed
RHEL 8
0:1.1.32-5.el8
fixed
libxslt-devel
RHEL 7
0:1.1.28-6.el7
fixed
RHEL 8
0:1.1.32-5.el8
fixed
libxslt-python
RHEL 7
0:1.1.28-6.el7
fixed
References