CVE-2011-1425
Summary
| CVE | CVE-2011-1425 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-04-04 12:27:57 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aleksey | Xml Security Library | 0.0.1 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.10 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.11 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.12 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.13 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.14 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.15 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.2 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.2a | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.3 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.4 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.5 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.6 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.7 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.8 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.0.9 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.1.0 | All | All | All |
| Application | Aleksey | Xml Security Library | 0.1.1 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.0.0 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.0.0 | rc1 | All | All |
| Application | Aleksey | Xml Security Library | 1.0.1 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.0.2 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.0.3 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.0.4 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.1.0 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.1.1 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.1.2 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.0 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.1 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.10 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.11 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.13 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.14 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.15 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.2 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.3 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.4 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.5 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.6 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.7 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.8 | All | All | All |
| Application | Aleksey | Xml Security Library | 1.2.9 | All | All | All |
| Application | Aleksey | Xml Security Library | All | All | All | All |
| Application | Apple | Webkit | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Bug 692133 – CVE-2011-1425 xmlsec1: arbitrary file creation when verifying signatures | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| Sign in · GitLab | af854a3a-2127-422b-91ae-364da2661108 | git.gnome.org | Patch |
| Debian update for xmlsec1 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Changeset 79159 – WebKit | af854a3a-2127-422b-91ae-364da2661108 | trac.webkit.org | |
| Sign in · GitLab | af854a3a-2127-422b-91ae-364da2661108 | git.gnome.org | Patch |
| XML Security Library XSLT File Access Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugs.webkit.org | |
| XML Security Library XSLT Signature Verification Bug Lets Remote Users Create or Overwrite Files on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Support / Security / Advisories / / MDVSA-2011:063 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Debian -- Security Information -- DSA-2219-1 xmlsec1 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [xmlsec] New xmlsec 1.2.17 release | af854a3a-2127-422b-91ae-364da2661108 | www.aleksey.com | Patch |
| XML Security Library 'xslt.c' Arbitrary File Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Red Hat update for xmlsec1 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.