RETIRED:libxslt 'xsltGenerateIdFunction()' Function Heap Memory Information Disclosure Vulnerability
BID:46818
Info
RETIRED:libxslt 'xsltGenerateIdFunction()' Function Heap Memory Information Disclosure Vulnerability
| Bugtraq ID: | 46818 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2011 12:00AM |
| Updated: | May 11 2011 03:12PM |
| Credit: | Chris Evans |
| Vulnerable: |
XMLSoft libxslt 1.1.24 XMLSoft libxslt 1.1.23 XMLSoft libxslt 1.1.22 XMLSoft libxslt 1.1.21 XMLSoft libxslt 1.1.20 XMLSoft libxslt 1.1.19 XMLSoft libxslt 1.1.18 XMLSoft libxslt 1.1.17 XMLSoft libxslt 1.1.16 XMLSoft libxslt 1.1.15 XMLSoft libxslt 1.1.14 XMLSoft libxslt 1.1.13 XMLSoft libxslt 1.1.12 XMLSoft libxslt 1.1.11 XMLSoft libxslt 1.1.10 XMLSoft libxslt 1.1.9 XMLSoft libxslt 1.1.8 XMLSoft libxslt 1.0.33 XMLSoft libxslt 1.0.15 XMLSoft libxslt 1.1.26 XMLSoft libxslt 1.1.25 Mozilla Firefox 3.6.13 Mozilla Firefox 3.6.13 Mozilla Firefox 3.6.10 Mozilla Firefox 3.6.9 Mozilla Firefox 3.6.8 Mozilla Firefox 3.6.6 Mozilla Firefox 3.6.4 Mozilla Firefox 3.6.3 Mozilla Firefox 3.6.2 Mozilla Firefox 3.6.2 Mozilla Firefox 3.5.17 Mozilla Firefox 3.5.16 Mozilla Firefox 3.5.14 Mozilla Firefox 3.5.13 Mozilla Firefox 3.5.10 Mozilla Firefox 3.5.10 Mozilla Firefox 3.5.9 Mozilla Firefox 3.5.9 Mozilla Firefox 3.5.8 Mozilla Firefox 3.5.7 Mozilla Firefox 3.5.6 Mozilla Firefox 3.5.5 Mozilla Firefox 3.5.4 Mozilla Firefox 3.5.3 Mozilla Firefox 3.5.2 Mozilla Firefox 3.5.1 Mozilla Firefox 3.5 Mozilla Firefox 3.6.7 Mozilla Firefox 3.6.6 Mozilla Firefox 3.6.14 Mozilla Firefox 3.6.12 Mozilla Firefox 3.6.11 Mozilla Firefox 3.6 Beta 3 Mozilla Firefox 3.6 Beta 2 Mozilla Firefox 3.6 Mozilla Firefox 3.5.17 Mozilla Firefox 3.5.15 Mozilla Firefox 3.5.12 Mozilla Firefox 3.5.11 Microsoft Internet Explorer 8 Apple Safari 5.0.4 for Windows Apple Safari 5.0.4 Apple Safari 5.0.3 for Windows Apple Safari 5.0.3 Apple Safari 5.0.2 for Windows Apple Safari 5.0.2 Apple Safari 5.0.1 for Windows Apple Safari 5.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2 beta Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.0 |
| Not Vulnerable: |
Apple iOS 4.3.2 |
Discussion
RETIRED:libxslt 'xsltGenerateIdFunction()' Function Heap Memory Information Disclosure Vulnerability
The 'libxslt' library is prone to a remote information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information that may aid in further attacks.
NOTE: Several web browsers use the 'libxslt' library.
NOTE: This BID is being retired as a duplicate of BID 47668.
The 'libxslt' library is prone to a remote information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information that may aid in further attacks.
NOTE: Several web browsers use the 'libxslt' library.
NOTE: This BID is being retired as a duplicate of BID 47668.
Exploit / POC
RETIRED:libxslt 'xsltGenerateIdFunction()' Function Heap Memory Information Disclosure Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user into visiting a specially crafted webpage.
Attackers can exploit this issue by enticing an unsuspecting user into visiting a specially crafted webpage.
Solution / Fix
RETIRED:libxslt 'xsltGenerateIdFunction()' Function Heap Memory Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
RETIRED:libxslt 'xsltGenerateIdFunction()' Function Heap Memory Information Disclosure Vulnerability
References:
References:
- Fix generate-id() to not expose object addresses (Daniel Veillard)
- Internet Explorer Homepage (Microsoft)
- libxslt Homepage (XMLSoft)
- Mozilla Firefox Homepage (Mozilla)
- Multi-browser heap address leak in XSLT (Chris Evans)
- Safari Homepage (Apple)