Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

Mandriva: Subject: [Security Announce] [ MDVSA-2008:160 ] libxslt

BugsAlert Home > Mandriva: Subject: [Security Announce] [ MDVSA-2008:160 ] libxslt
 
 

LinuxSecurity.com: Chris Evans of the Google Security Team found a vulnerability in the RC4 processing code in libxslt that did not properly handle corrupted key information. A remote attacker able to make an application linked against libxslt process malicious XML input could cause the application to crash or possibly execute arbitrary code with the privileges of the application in question (CVE-2008-2935). The updated packages have been patched to correct this issue.




Original Source: http://www.linuxsecurity.com/content/view/140867?rdf

Learn more about Mandriva: Subject: [Security Announce] [ MDVSA-2008:160 ] libxslt
 
Tags: mandriva subject security announce mdvsa-2008 160 libxslt

Related Items

      Avira 2008

      Vuln: Microgaming Download Helper ActiveX Control Remote Buffer Overflow Vulnerability

      CVE-2008-3093 (imperialbb)

      Slackware update for firefox

      Fedora update for xine-lib

      FrSIRT - SuSE Security Update Fixes Multiple Buffer Overflow Vulnerabilities

      EXPL_MS04-028.A

 

Pixel