Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 12.10 USN-1784-1 Critical: libxslt Denial of Service

ubuntu
Calendar Grey April 2, 2013
Scroller Ubuntu
The vulnerability in Libxslt impacts various Ubuntu releases, which could lead to system crashes when handling specially designed files.
Applications using libxslt could be made to crash if they processed a specially crafted file.

Summary

Applications using libxslt could be made to crash if they processed a

specially crafted file.

Software Description:

- libxslt: XSLT processing library

Details:

Nicholas Gregoire discovered that libxslt incorrectly handled certain empty

values. If a user or automated system were tricked into processing a

specially crafted XSLT document, a remote attacker could cause libxslt to

crash, causing a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  libxslt1.1                      1.1.26-14ubuntu0.1

Ubuntu 12.04 LTS:
  libxslt1.1                      1.1.26-8ubuntu1.3

Ubuntu 11.10:
  libxslt1.1                      1.1.26-7ubuntu0.2

Ubuntu 10.04 LTS:
  libxslt1.1                      1.1.26-1ubuntu1.2

Ubuntu 8.04 LTS:
  libxslt1.1                      1.1.22-1ubuntu1.4

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1784-1

CVE-2012-6139

Severity
critical
Lowest
Low
Medium
High
Critical

April 02, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.