libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2019-04-10 20:29
Updated : 2020-08-24 17:37
NVD link : CVE-2019-11068
Mitre link : CVE-2019-11068
JSON object : View
Products Affected
debian
- debian_linux
canonical
- ubuntu_linux
xmlsoft
- libxslt
CWE
