cbcvebase.
CVE-2019-11068
published 2019-04-10

CVE-2019-11068: libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

Affected

20 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlibxslt< libxslt 1.1.32-2.1 (bookworm)libxslt 1.1.32-2.1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
netappe-series_santricity_os_controller11.0 – 11.70.2
nokogirinokogiri>= 0 < 1.10.31.10.3
opensuseleap
opensuseleap
opensuseleap
oraclejdk
xmlsoftlibxslt<= 1.1.33
xmlsoftlibxslt>= 0 < 1.1.32-2.11.1.32-2.1
xmlsoftlibxslt>= 0 < 1.1.32-2.11.1.32-2.1
xmlsoftlibxslt>= 0 < 1.1.32-2.11.1.32-2.1
xmlsoftlibxslt>= 0 < 1.1.32-2.11.1.32-2.1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL