CVE-2011-1202
published 2011-03-11CVE-2011-1202: The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.44%
82.6th percentile
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| debian | libxslt | < libxslt 1.1.26-7 (bookworm) | libxslt 1.1.26-7 (bookworm) |
| chrome | < 10.0.648.127 | 10.0.648.127 | |
| microsoft | internet_explorer | — | — |
| vmware | esxi | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vsphere | — | — |
| xmlsoft | libxslt | <= 1.1.26 | — |
| xmlsoft | libxslt | >= 0 < 1.1.26-7 | 1.1.26-7 |
| xmlsoft | libxslt | >= 0 < 1.1.26-7 | 1.1.26-7 |
| xmlsoft | libxslt | >= 0 < 1.1.26-7 | 1.1.26-7 |
| xmlsoft | libxslt | >= 0 < 1.1.26-7 | 1.1.26-7 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_ubuntu10.0CRITICAL
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vSphere security updates for the authentication service and third party libraries
vendor_vmware·2013-01-31·CVSS 10.0
CVE-2011-1202 [CRITICAL] VMware vSphere security updates for the authentication service and third party libraries
VMSA-2013-0001: VMware vSphere security updates for the authentication service and third party libraries
a. VMware vSphere client-side authentication memory corruption vulnerability VMware vCenter Server, vSphere Client, and ESX contain a vulnerability in the handling of the management authentication protocol. To exploit this vulnerability, an attacker must convince either vCenter Server, vSphere Client or ESX to interact with a malicious server as a client. Exploitation of the issue may lead to code execution on the client system. To reduce the likelihood of exploitation, vSphere components should be deployed on an isolated management network. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2013-1405 to this issue. Column 4 of the following tabl
VMware
VMware security updates for vCSA, vCenter Server, and ESXi
vendor_vmware·2012-12-20·CVSS 4.0
CVE-2009-5029 [MEDIUM] VMware security updates for vCSA, vCenter Server, and ESXi
VMSA-2012-0018: VMware security updates for vCSA, vCenter Server, and ESXi
a. vCenter Server Appliance directory traversal The vCenter Server Appliance (vCSA) contains a directory traversal vulnerability that allows an authenticated remote user to retrieve arbitrary files. Exploitation of this issue may expose sensitive information stored on the server. VMware would like to thank Alexander Minozhenko from ERPScan for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-6324 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product vCSA Product Vers
Ubuntu
libxslt vulnerabilities
vendor_ubuntu·2012-10-04·CVSS 4.3
CVE-2011-1202 [MEDIUM] libxslt vulnerabilities
Title: libxslt vulnerabilities
Summary: Applications using libxslt could be made to crash or run programs as your
login if they processed a specially crafted file.
Chris Evans discovered that libxslt incorrectly handled generate-id XPath
functions. If a user or automated system were tricked into processing a
specially crafted XSLT document, a remote attacker could obtain potentially
sensitive information. This issue only affected Ubuntu 8.04 LTS, Ubuntu
10.04 LTS and Ubuntu 11.04. (CVE-2011-1202)
It was discovered that libxslt incorrectly parsed certain patterns. If a
user or automated system were tricked into processing a specially crafted
XSLT document, a remote attacker could cause libxslt to crash, causing a
denial of service. (CVE-2011-3970)
Nicholas Gregoire discovered that libxs
Ubuntu
Thunderbird regression
vendor_ubuntu·2011-06-06·CVSS 10.0
[CRITICAL] Thunderbird regression
Title: Thunderbird regression
Summary: An empty menu bar sometimes appeared after upgrade in USN-1122-2
USN-1122-2 fixed vulnerabilities in Thunderbird on Ubuntu 11.04. A
regression was introduced which caused Thunderbird to display an empty menu
bar. This update fixes the problem. We apologize for the inconvenience.
Original advisory details:
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0081)
It was discovered that Thunderbird incorrectly handled certain JavaScript
requests. If JavaScript were enabled, an attacker could exploit this to
possibly run arbitrary code as the user running Thunderbird.
(CVE-2011-0069)
Ian Beer disc
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-05-05·CVSS 10.0
CVE-2011-0065 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird could be made to run programs as your login if it opened
specially crafted mail.
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0081)
It was discovered that Thunderbird incorrectly handled certain JavaScript
requests. If JavaScript were enabled, an attacker could exploit this to
possibly run arbitrary code as the user running Thunderbird.
(CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a certain
types of documents. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0070)
Bob Clary, Henri Siv
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2011-05-05·CVSS 10.0
CVE-2011-0065 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird could be made to run programs as your login if it opened
specially crafted mail.
USN-1122-1 fixed vulnerabilities in Thunderbird for Lucid and Maverick.
This update provides the corresponding fixes for Natty.
Original advisory details:
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Thunderbird. (CVE-2011-0081)
It was discovered that Thunderbird incorrectly handled certain JavaScript
requests. If JavaScript were enabled, an attacker could exploit this to
possibly run arbitrary code as the user running Thunderbird.
(CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a cer
Ubuntu
Xulrunner vulnerabilities
vendor_ubuntu·2011-04-30
CVE-2011-0077 Xulrunner vulnerabilities
Title: Xulrunner vulnerabilities
Summary: Multiple xulrunner-1.9.1 vulnerabilities
A large number of security issues were discovered in the Gecko rendering
engine. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: After a standard system update you need to restart any applications which
use Xulrunner to make all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2011-04-30·CVSS 10.0
CVE-2011-0079 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Multiple firefox vulnerabilities
Boris Zbarsky, Gary Kwong, Jesse Ruderman, Michael Wu, and Ted Mielczarek
discovered multiple memory vulnerabilities. An attacker could exploit these
to possibly run arbitrary code as the user running Firefox. (CVE-2011-0079)
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Firefox. (CVE-2011-0081)
It was discovered that Firefox incorrectly handled certain JavaScript
requests. An attacker could exploit this to possibly run arbitrary code as
the user running Firefox. (CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a certain
types of documents. An attack
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2011-04-29·CVSS 10.0
CVE-2011-0081 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Multiple vulnerabilities in Firefox and Xulrunner
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Firefox. (CVE-2011-0081)
It was discovered that Firefox incorrectly handled certain JavaScript
requests. An attacker could exploit this to possibly run arbitrary code as
the user running Firefox. (CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a certain
types of documents. An attacker could exploit this to possibly run
arbitrary code as the user running Firefox. (CVE-2011-0070)
Bob Clary, Henri Sivonen, Marco Bonardo, Mats Palmgren and Jesse Ruderman
discovered several memo
Red Hat
libxslt: Heap address leak in XLST
vendor_redhat·2011-02-22·CVSS 4.3
CVE-2011-1202 [MEDIUM] libxslt: Heap address leak in XLST
libxslt: Heap address leak in XLST
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
Statement: This issue affects the versions of libxslt package as shipped with Red Hat
Enterprise Linux 4, 5 and 6. The Red Hat Security Response Team has rated this
issue as having low security impact, a future update may address this flaw.
Package: libxslt (Red Hat Enterprise Linux 4) - Will not fix
Package: mingw32-libxslt (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2011-1202: libxslt - The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier...
vendor_debian·2011·CVSS 4.3
CVE-2011-1202 [MEDIUM] CVE-2011-1202: libxslt - The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier...
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
Scope: local
bookworm: resolved (fixed in 1.1.26-7)
bullseye: resolved (fixed in 1.1.26-7)
forky: resolved (fixed in 1.1.26-7)
sid: resolved (fixed in 1.1.26-7)
trixie: resolved (fixed in 1.1.26-7)
GHSA
GHSA-jh8p-g678-fj3r: The generate-id XPath function in libxslt in Apple iOS 4
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2011-0195 [MEDIUM] CWE-200 GHSA-jh8p-g678-fj3r: The generate-id XPath function in libxslt in Apple iOS 4
The generate-id XPath function in libxslt in Apple iOS 4.3.x before 4.3.2 allows remote attackers to obtain potentially sensitive information about heap memory addresses via a crafted web site. NOTE: this may overlap CVE-2011-1202.
GHSA
GHSA-vrgp-pjr9-mp64: The xsltGenerateIdFunction function in functions
ghsa_unreviewed·2022-05-13
CVE-2011-1202 [MEDIUM] CWE-200 GHSA-vrgp-pjr9-mp64: The xsltGenerateIdFunction function in functions
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
GHSA
GHSA-w256-55mp-mjfh: Microsoft msxml
ghsa_unreviewed·2022-05-13·CVSS 4.3
CVE-2011-1713 [MEDIUM] CWE-200 GHSA-w256-55mp-mjfh: Microsoft msxml
Microsoft msxml.dll, as used in Internet Explorer 8 on Windows 7, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. NOTE: this might overlap CVE-2011-1202.
OSV
CVE-2011-1202: The xsltGenerateIdFunction function in functions
osv·2011-03-11·CVSS 4.3
CVE-2011-1202 [MEDIUM] CVE-2011-1202: The xsltGenerateIdFunction function in functions
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1712 firefox: information leak due to XSLT
bugzilla·2011-04-19·CVSS 4.3
CVE-2011-1712 [MEDIUM] CVE-2011-1712 firefox: information leak due to XSLT
CVE-2011-1712 firefox: information leak due to XSLT
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1712 to
the following vulnerability:
Name: CVE-2011-1712
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1712
Assigned: 20110415
Reference: http://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.html
The txXPathNodeUtils::getXSLTId function in
txStandaloneXPathTreeWalker.cpp in Mozilla Firefox 3.6.16 and earlier
allows remote attackers to obtain potentially sensitive information
about heap memory addresses via an XML document containing a call to
the XSLT generate-id XPath function.
This flaw is the same root issue as CVE-2011-1202 (in libxslt).
Bugzilla
CVE-2011-1202 libxslt: Heap address leak in XLST
bugzilla·2011-03-12·CVSS 4.3
CVE-2011-1202 [MEDIUM] CVE-2011-1202 libxslt: Heap address leak in XLST
CVE-2011-1202 libxslt: Heap address leak in XLST
Chris Evans discovered a heap address leak in XSLT
The bug is in the generate-id() XPath function, and is
sometimes used in XSL transforms.
This is a low severity information leak, that does not
corrupt anything, However it can be paired with other
bugs and can be perhaps used as an exploit aid against
ASLR.
References:
http://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.html
http://git.gnome.org/browse/libxslt/commit/?id=ecb6bcb8d1b7e44842edde3929f412d46b40c89f
This has been assigned CVE-2011-1202.
Discussion:
Created libxslt tracking bugs for this issue
Affects: fedora-all [bug 684388]
---
Statement:
This issue affects the versions of libxslt package as shipped with Red Hat
Enterprise Linux 4, 5
Bugzilla
CVE-2011-1202 libxslt: Heap address leak in XLST [fedora-all]
bugzilla·2011-03-12·CVSS 4.3
CVE-2011-1202 [MEDIUM] CVE-2011-1202 libxslt: Heap address leak in XLST [fedora-all]
CVE-2011-1202 libxslt: Heap address leak in XLST [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=684386
Please note: this issue affects multiple supported ve
http://code.google.com/p/chromium/issues/detail?id=73716http://downloads.avaya.com/css/P8/documents/100144158http://git.gnome.org/browse/libxslt/commit/?id=ecb6bcb8d1b7e44842edde3929f412d46b40c89fhttp://googlechromereleases.blogspot.com/2011/03/chrome-stable-release.htmlhttp://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:079http://www.mandriva.com/security/advisories?name=MDVSA-2012:164http://www.securityfocus.com/bid/46785http://www.vupen.com/english/advisories/2011/0628https://bugzilla.redhat.com/show_bug.cgi?id=684386https://exchange.xforce.ibmcloud.com/vulnerabilities/65966https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14244http://code.google.com/p/chromium/issues/detail?id=73716http://downloads.avaya.com/css/P8/documents/100144158http://git.gnome.org/browse/libxslt/commit/?id=ecb6bcb8d1b7e44842edde3929f412d46b40c89fhttp://googlechromereleases.blogspot.com/2011/03/chrome-stable-release.htmlhttp://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:079http://www.mandriva.com/security/advisories?name=MDVSA-2012:164http://www.securityfocus.com/bid/46785http://www.vupen.com/english/advisories/2011/0628https://bugzilla.redhat.com/show_bug.cgi?id=684386https://exchange.xforce.ibmcloud.com/vulnerabilities/65966https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14244
2011-03-11
Published