漏洞信息详情
libxslt 访问控制错误漏洞
漏洞简介
libxslt是一款XSLT(用于定义XML转换的XML语言)C库。
libxslt 1.1.33及之前版本中存在安全漏洞,该漏洞源于当xsltCheckRead和xsltCheckWrite返回‘-1’时,callers函数并没有对其进程检测并允许进行访问。攻击者可利用该漏洞绕过保护机制。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6
参考网址
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00001.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00048.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00052.html
来源:MISC
链接:https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/GCOAX2IHUMKCM3ILHTMGLHCDSBTLP2JU/
来源:gitlab.gnome.org
链接:https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2019/04/23/5
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/36TEYN37XCCKN2XUMRTBBW67BPNMSW4K/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/SK4YNISS22MJY22YX5I6V2U63QZAUEHA/
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20191017-0001/
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00025.html
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2019/04/22/1
来源:UBUNTU
链接:https://usn.ubuntu.com/3947-1/
来源:UBUNTU
链接:https://usn.ubuntu.com/3947-2/
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2019/04/msg00016.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00053.html
来源:security-tracker.debian.org
链接:https://security-tracker.debian.org/tracker/DLA-1756-1
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191221-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191381-1.html
来源:usn.ubuntu.com
链接:https://usn.ubuntu.com/3947-1/
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191232-1.html
来源:security.business.xerox.com
链接:https://security.business.xerox.com/wp-content/uploads/2019/11/cert_XRX19-029_FFPSv2_Win10_SecurityBulletin_Nov2019.pdf
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-11068
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-appliance-is-affected-by-libxslt-vulnerabilities-cve-2019-11068-cve-2019-18197/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79098
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161546/Red-Hat-Security-Advisory-2020-5633-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161429/Red-Hat-Security-Advisory-2021-0436-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79134
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159869/Red-Hat-Security-Advisory-2020-4464-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4513/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-network-security-is-affected-by-multiple-vulnerabilities-2/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0234/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0584
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3830/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3397/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160624/Red-Hat-Security-Advisory-2020-5605-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80926
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152521/Ubuntu-Security-Notice-USN-3947-2.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0864
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/libxslt-read-write-via-xsltCheckRead-xsltCheckWrite-29040
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159387/Red-Hat-Security-Advisory-2020-4005-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.4343/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2604
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80790
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0692
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159661/Red-Hat-Security-Advisory-2020-4264-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3631/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.1942/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161742/Red-Hat-Security-Advisory-2021-0799-01.html
受影响实体
暂无
补丁
- libxslt 安全漏洞的修复措施<!--2019-4-10-->
还没有评论,来说两句吧...