VDB
CVE-2011-1425
CVE-2011-1425
PUBLISHED
CVSS 5.099999904632568 MEDIUM
xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.
EPSS 8.06% · 94.6th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
8.06%
94.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | webkit | |
| aleksey | xml_security_library | 0, 0.0.1, 0.0.2a |
| n/a | n/a | n/a |
Timeline
- Apr 3, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
References
- 44423 third-party-advisory
- https://bugs.webkit.org/show_bug.cgi?id=52688 url
- http://git.gnome.org/browse/xmlsec/commit/?id=2d5eddcc4163ea050cf3a3a1a25452bb5124f780 url
- ADV-2011-1172 vdb
- 43920 third-party-advisory
- http://git.gnome.org/browse/xmlsec/commit/?id=35eaacde6093d6711339754fc2146341b8b9f5fa patch
- http://www.aleksey.com/pipermail/xmlsec/2011/009120.html patch
- http://www.vupen.com/english/advisories/2011/0855 technical
- http://www.vupen.com/english/advisories/2011/0858 technical
- http://secunia.com/advisories/44167 technical
- http://trac.webkit.org/changeset/79159 technical
- http://www.redhat.com/support/errata/RHSA-2011-0486.html technical
- http://www.securityfocus.com/bid/47135 technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66506 technical
- https://nvd.nist.gov/vuln/detail/CVE-2011-1425 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=692133 url
- http://www.debian.org/security/2011/dsa-2219 url
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:063 url
- http://www.securitytracker.com/id?1025284 url
- http://www.vupen.com/english/advisories/2011/1010 url