Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Debian: 2020-0308 Severe: openldap Directory Traversal Vulnerability

mageia
Calendar Grey May 18, 2019
Dist Mageia Esm H88
The latest libxslt updates rectify significant access control vulnerabilities in Mageia, enabling potential bypass. Comprehensive security patch information is available.
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code

Summary

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded (CVE-2019-11068).

References

- https://bugs.mageia.org/show_bug.cgi?id=24705

- https://ubuntu.com/security/notices/USN-3947-1

- https://www.cve.org/CVERecord?id=CVE-2019-11068

Resolution

SRPMS

- 6/core/libxslt-1.1.29-6.1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 18 May 2019
URL: https://advisories.mageia.org/MGASA-2019-0175.html
Type: security
CVE: CVE-2019-11068

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here