Oval Definition:oval:org.opensuse.security:def:20082935
Revision Date:2015-11-16Version:1
Title:CVE-2008-2935
Description:
Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."
Family:unixClass:vulnerability
Status:Reference(s):CVE-2008-2935
Platform(s):openSUSE 10.2
openSUSE 10.3
openSUSE 11.0
Product(s):
Definition Synopsis
  • suse110 is installed
  • AND Package Information
  • libxslt-32bit less than 1.1.23-13.2
  • OR libxslt-64bit less than 1.1.23-13.2
  • OR libxslt-devel-32bit less than 1.1.23-13.2
  • OR libxslt-devel-64bit less than 1.1.23-13.2
  • OR libxslt-devel less than 1.1.23-13.2
  • OR libxslt less than 1.1.23-13.2
  • BACK