CVE-2019-11068
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.23% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- xmlsoft/libxslt · canonical/ubuntu linux · debian/debian linux · fedoraproject/fedora · oracle/jdk · netapp/active iq unified manager · netapp/cloud backup · netapp/e-series santricity management plug-ins · netapp/e-series santricity os controller · netapp/e-series santricity storage manager · netapp/e-series santricity unified manager · netapp/e-series santricity web services proxy · netapp/element software · netapp/hci management node · netapp/oncommand insight · netapp/oncommand workflow automation · netapp/plug-in for symantec netbackup · netapp/santricity unified manager · netapp/snapmanager · netapp/solidfire · +2 more
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00048.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00052.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00053.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00025.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00001.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/22/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/23/5Mailing List, Third Party Advisory
- https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00016.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36TEYN37XCCKN2XUMRTBBW67BPNMSW4K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCOAX2IHUMKCM3ILHTMGLHCDSBTLP2JU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SK4YNISS22MJY22YX5I6V2U63QZAUEHA/
- https://security.netapp.com/advisory/ntap-20191017-0001/Third Party Advisory
- https://usn.ubuntu.com/3947-1/Third Party Advisory
- https://usn.ubuntu.com/3947-2/Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00048.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00052.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00053.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00025.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00001.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/22/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/23/5Mailing List, Third Party Advisory
- https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00016.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36TEYN37XCCKN2XUMRTBBW67BPNMSW4K/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCOAX2IHUMKCM3ILHTMGLHCDSBTLP2JU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SK4YNISS22MJY22YX5I6V2U63QZAUEHA/
- https://security.netapp.com/advisory/ntap-20191017-0001/Third Party Advisory
- https://usn.ubuntu.com/3947-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.