Gentoo Archives: gentoo-announce

From: Tobias Heinlein <keytoaster@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200808-06 ] libxslt: Execution of arbitrary code
Date: Wed, 06 Aug 2008 20:26:25
Message-Id: 489A0724.4080308@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200808-06
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: libxslt: Execution of arbitrary code
9 Date: August 06, 2008
10 Bugs: #232172
11 ID: 200808-06
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 libxslt is affected by a heap-based buffer overflow, possibly leading
19 to the execution of arbitrary code.
20
21 Background
22 ==========
23
24 libxslt is the XSLT C library developed for the GNOME project. XSLT is
25 an XML language to define transformations for XML.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 dev-libs/libxslt < 1.1.24-r1 >= 1.1.24-r1
34 < 1.1.8
35
36 Description
37 ===========
38
39 Chris Evans (Google Security) reported that the libexslt library that
40 is part of libxslt is affected by a heap-based buffer overflow in the
41 RC4 encryption/decryption functions.
42
43 Impact
44 ======
45
46 A remote attacker could entice a user to process an XML file using a
47 specially crafted XSLT stylesheet in an application linked against
48 libxslt, possibly leading to the execution of arbitrary code with the
49 privileges of the user running the application.
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time.
55
56 Resolution
57 ==========
58
59 All libxslt users should upgrade to the latest version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose ">=dev-libs/libxslt-1.1.24-r1"
63
64 References
65 ==========
66
67 [ 1 ] CVE-2008-2935
68 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2935
69
70 Availability
71 ============
72
73 This GLSA and any updates to it are available for viewing at
74 the Gentoo Security Website:
75
76 http://security.gentoo.org/glsa/glsa-200808-06.xml
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 http://bugs.gentoo.org.
86
87 License
88 =======
89
90 Copyright 2008 Gentoo Foundation, Inc; referenced text
91 belongs to its owner(s).
92
93 The contents of this document are licensed under the
94 Creative Commons - Attribution / Share Alike license.
95
96 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature