Heap-Based Buffer Overflow in libxslt by Red Hat
CVE-2008-2935

Currently unrated

Key Information:

Vendor

Xmlsoft

Status
Vendor
CVE Published:
1 August 2008

What is CVE-2008-2935?

The vulnerability in libxslt affects its processing of XML files where attackers can exploit multiple heap-based buffer overflows in the rc4 encryption and decryption functions. By crafting an XML file with a lengthy string as an argument in the XSL input, it allows the execution of arbitrary code, jeopardizing the security of the affected system.

References

EPSS Score

20% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.