CVE-2019-11068
published 2019-04-10CVE-2019-11068: libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.09%
91.4th percentile
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxslt | < libxslt 1.1.32-2.1 (bookworm) | libxslt 1.1.32-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| netapp | e-series_santricity_os_controller | 11.0 – 11.70.2 | — |
| nokogiri | nokogiri | >= 0 < 1.10.3 | 1.10.3 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | jdk | — | — |
| xmlsoft | libxslt | <= 1.1.33 | — |
| xmlsoft | libxslt | >= 0 < 1.1.32-2.1 | 1.1.32-2.1 |
| xmlsoft | libxslt | >= 0 < 1.1.32-2.1 | 1.1.32-2.1 |
| xmlsoft | libxslt | >= 0 < 1.1.32-2.1 | 1.1.32-2.1 |
| xmlsoft | libxslt | >= 0 < 1.1.32-2.1 | 1.1.32-2.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libxslt vulnerability
vendor_ubuntu·2019-04-15
CVE-2019-11068 Libxslt vulnerability
Title: Libxslt vulnerability
Summary: Libxslt could be made to expose sensitive information if it
received a specially crafted file.
USN-3947-1 fixed a vulnerability in Libxslt. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Libxslt incorrectly handled certain documents.
An attacker could possibly use this issue to access sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Libxslt vulnerability
vendor_ubuntu·2019-04-15
CVE-2019-11068 Libxslt vulnerability
Title: Libxslt vulnerability
Summary: Libxslt could be made to expose sensitive information if it received
a specially crafted file.
It was discovered that Libxslt incorrectly handled certain documents.
An attacker could possibly use this issue to access sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL
vendor_redhat·2019-04-10·CVSS 9.8
CVE-2019-11068 [CRITICAL] CWE-284 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL
libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Statement: Red Hat OpenStack will consume fixes from the base Red Hat Enterprise Linux Operating System. Therefore the package provided by Red Hat OpenStack has been marked as will not fix.
Mitigation: This flaw only applies to applications compiled against libxml2 which use xsltCheckRead and xsltCheckWrite functions and/or allow users to load arbitrary URLs to be parsed via libxml2. In all other cases, applications are not vulnerable.
Packa
Debian
CVE-2019-11068: libxslt - libxslt through 1.1.33 allows bypass of a protection mechanism because callers o...
vendor_debian·2019·CVSS 9.8
CVE-2019-11068 [CRITICAL] CVE-2019-11068: libxslt - libxslt through 1.1.33 allows bypass of a protection mechanism because callers o...
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Scope: local
bookworm: resolved (fixed in 1.1.32-2.1)
bullseye: resolved (fixed in 1.1.32-2.1)
forky: resolved (fixed in 1.1.32-2.1)
sid: resolved (fixed in 1.1.32-2.1)
trixie: resolved (fixed in 1.1.32-2.1)
OSV
Nokogiri vulnerable to libxslt protection mechanism bypass
osv·2022-05-13
CVE-2019-11068 [CRITICAL] Nokogiri vulnerable to libxslt protection mechanism bypass
Nokogiri vulnerable to libxslt protection mechanism bypass
A dependency of Nokogiri, libxslt through 1.1.33 allows bypass of a protection mechanism because callers of `xsltCheckRead` and `xsltCheckWrite` permit access even upon receiving a `-1` error code. `xsltCheckRead` can return `-1` for a crafted URL that is not actually invalid and is subsequently loaded.
GHSA
Nokogiri vulnerable to libxslt protection mechanism bypass
ghsa·2022-05-13
CVE-2019-11068 [CRITICAL] Nokogiri vulnerable to libxslt protection mechanism bypass
Nokogiri vulnerable to libxslt protection mechanism bypass
A dependency of Nokogiri, libxslt through 1.1.33 allows bypass of a protection mechanism because callers of `xsltCheckRead` and `xsltCheckWrite` permit access even upon receiving a `-1` error code. `xsltCheckRead` can return `-1` for a crafted URL that is not actually invalid and is subsequently loaded.
OSV
CVE-2019-11068: libxslt through 1
osv·2019-04-10·CVSS 9.8
CVE-2019-11068 [CRITICAL] CVE-2019-11068: libxslt through 1
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11068 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL
bugzilla·2019-05-14·CVSS 9.8
CVE-2019-11068 [CRITICAL] CVE-2019-11068 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL
CVE-2019-11068 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Upstream commit:
https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6
Discussion:
Created libxslt tracking bugs for this issue:
Affects: fedora-all [bug 1709698]
Created mingw-libxslt tracking bugs for this issue:
Affects: fedora-all [bug 1709699]
---
This is basically a flaw in how errors are propagated in libxslt. Both xsltCheckRead and xsltCheckWrite functions return -1 in case of err
Bugzilla
CVE-2019-11068 mingw-libxslt: libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL [fedora-all]
bugzilla·2019-05-14·CVSS 9.8
CVE-2019-11068 [CRITICAL] CVE-2019-11068 mingw-libxslt: libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL [fedora-all]
CVE-2019-11068 mingw-libxslt: libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2019-11068 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL [fedora-all]
bugzilla·2019-05-14·CVSS 9.8
CVE-2019-11068 [CRITICAL] CVE-2019-11068 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL [fedora-all]
CVE-2019-11068 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00048.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00001.htmlhttp://www.openwall.com/lists/oss-security/2019/04/22/1http://www.openwall.com/lists/oss-security/2019/04/23/5https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6https://lists.debian.org/debian-lts-announce/2019/04/msg00016.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36TEYN37XCCKN2XUMRTBBW67BPNMSW4K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCOAX2IHUMKCM3ILHTMGLHCDSBTLP2JU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SK4YNISS22MJY22YX5I6V2U63QZAUEHA/https://security.netapp.com/advisory/ntap-20191017-0001/https://usn.ubuntu.com/3947-1/https://usn.ubuntu.com/3947-2/https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00048.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00001.htmlhttp://www.openwall.com/lists/oss-security/2019/04/22/1http://www.openwall.com/lists/oss-security/2019/04/23/5https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6https://lists.debian.org/debian-lts-announce/2019/04/msg00016.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36TEYN37XCCKN2XUMRTBBW67BPNMSW4K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCOAX2IHUMKCM3ILHTMGLHCDSBTLP2JU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SK4YNISS22MJY22YX5I6V2U63QZAUEHA/https://security.netapp.com/advisory/ntap-20191017-0001/https://usn.ubuntu.com/3947-1/https://usn.ubuntu.com/3947-2/https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-04-10
Published