VDB
CVE-2011-1425
CVE-2011-1425
PUBLISHED
CVSS 5.099999904632568 MEDIUM
xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.
EPSS 9.31% · 92.9th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
9.31%
92.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | webkit | |
| aleksey | xml_security_library | 0, 0.0.1, 0.0.2a |
| n/a | n/a | n/a |
Timeline
- Apr 3, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=692133 url
- ADV-2011-0855 vdb
- 1025284 vdb
- DSA-2219 vendor-advisory
- MDVSA-2011:063 vendor-advisory
- 47135 vdb
- http://trac.webkit.org/changeset/79159 url
- ADV-2011-1010 vdb
- [xmlsec] 20110331 New xmlsec 1.2.17 release mailing-list
- 44423 third-party-advisory
- http://git.gnome.org/browse/xmlsec/commit/?id=2d5eddcc4163ea050cf3a3a1a25452bb5124f780 url
- RHSA-2011:0486 vendor-advisory
- http://git.gnome.org/browse/xmlsec/commit/?id=35eaacde6093d6711339754fc2146341b8b9f5fa url
- ADV-2011-1172 vdb
- 44167 third-party-advisory
- 43920 third-party-advisory
- https://bugs.webkit.org/show_bug.cgi?id=52688 url
- ADV-2011-0858 vdb
- xmlsecurity-xmlfiles-sec-bypass(66506) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2011-1425 advisory