| MDVSA-2011:063: xmlsec1 |
|
|
|
| Écrit par Administrator |
| Mardi, 05 Avril 2011 23:00 |
|
A vulnerability was discovered and corrected in xmlsec1:
xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification (CVE-2011-1425). Packages for 2009.0 are provided as of the Extended Maintenance Program. Please visit this link to learn more: http://store.mandriva.com/product_info.php?cPath=149&products_id=490 The updated packages have been patched to correct this issue. |



























































