5
CVSSv2

CVE-2012-6139

Published: 12/04/2013 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

libxslt prior to 1.1.28 allows remote malicious users to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c.

Vulnerable Product Search on Vulmon Subscribe to Product

xmlsoft libxslt 1.1.21

xmlsoft libxslt 1.1.20

xmlsoft libxslt 1.1.13

xmlsoft libxslt 1.1.12

xmlsoft libxslt 1.1.11

xmlsoft libxslt 1.1.4

xmlsoft libxslt 1.1.3

xmlsoft libxslt 1.0.30

xmlsoft libxslt 1.0.29

xmlsoft libxslt 1.0.21

xmlsoft libxslt 1.0.20

xmlsoft libxslt 1.0.13

xmlsoft libxslt 1.0.12

xmlsoft libxslt 1.0.5

xmlsoft libxslt 1.0.4

xmlsoft libxslt 0.11.0

xmlsoft libxslt 0.10.0

xmlsoft libxslt 0.3.0

xmlsoft libxslt 0.2.0

xmlsoft libxslt 1.1.25

xmlsoft libxslt 1.1.24

xmlsoft libxslt 1.1.17

xmlsoft libxslt 1.1.16

xmlsoft libxslt 1.1.8

xmlsoft libxslt 1.1.7

xmlsoft libxslt 1.1.0

xmlsoft libxslt 1.0.33

xmlsoft libxslt 1.0.26

xmlsoft libxslt 1.0.25

xmlsoft libxslt 1.0.17

xmlsoft libxslt 1.0.16

xmlsoft libxslt 1.0.9

xmlsoft libxslt 1.0.8

xmlsoft libxslt 1.0.1

xmlsoft libxslt 1.0.0

xmlsoft libxslt 0.14.0

xmlsoft libxslt 0.7.0

xmlsoft libxslt 0.6.0

xmlsoft libxslt 1.1.23

xmlsoft libxslt 1.1.22

xmlsoft libxslt 1.1.15

xmlsoft libxslt 1.1.14

xmlsoft libxslt 1.1.6

xmlsoft libxslt 1.1.5

xmlsoft libxslt 1.0.32

xmlsoft libxslt 1.0.31

xmlsoft libxslt 1.0.24

xmlsoft libxslt 1.0.23

xmlsoft libxslt 1.0.22

xmlsoft libxslt 1.0.15

xmlsoft libxslt 1.0.14

xmlsoft libxslt 1.0.7

xmlsoft libxslt 1.0.6

xmlsoft libxslt 0.13.0

xmlsoft libxslt 0.12.0

xmlsoft libxslt 0.5.0

xmlsoft libxslt 0.4.0

xmlsoft libxslt

xmlsoft libxslt 1.1.26

xmlsoft libxslt 1.1.19

xmlsoft libxslt 1.1.18

xmlsoft libxslt 1.1.10

xmlsoft libxslt 1.1.9

xmlsoft libxslt 1.1.2

xmlsoft libxslt 1.1.1

xmlsoft libxslt 1.0.28

xmlsoft libxslt 1.0.27

xmlsoft libxslt 1.0.19

xmlsoft libxslt 1.0.18

xmlsoft libxslt 1.0.11

xmlsoft libxslt 1.0.10

xmlsoft libxslt 1.0.3

xmlsoft libxslt 1.0.2

xmlsoft libxslt 0.9.0

xmlsoft libxslt 0.8.0

xmlsoft libxslt 0.1.0

xmlsoft libxslt 0.0.1

opensuse opensuse 12.1

opensuse opensuse 11.4

opensuse opensuse 12.3

opensuse opensuse 12.2

Vendor Advisories

Debian Bug report logs - #703933 libxslt: CVE-2012-6139 Package: libxslt; Maintainer for libxslt is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 25 Mar 2013 22:18:02 UTC Severity: grave Tags: fixed-upstream, patch, security, ups ...
Applications using libxslt could be made to crash if they processed a specially crafted file ...
Nicolas Gregoire discovered that libxslt, an XSLT processing runtime library, is prone to denial of service vulnerabilities via crafted XSL stylesheets For the stable distribution (squeeze), this problem has been fixed in version 1126-6+squeeze3 For the testing distribution (wheezy), this problem has been fixed in version 1126-141 For the u ...