It was reported that the fix for CVE-2012-2825 was incomplete for versions of libxslt prior to 1.1.25. The same flaw is still present in those older versions of libxslt without this additional fix: https://gitorious.org/libxslt/libxslt/commit/7089a62b8f133b42a2981cf1f920a8b3fe9a8caa This never affected the versions of libxslt as provided with Red Hat Enterprise Linux 6 or Fedora. It was also corrected in Red Hat Enterprise Linux 5's libxslt as fixed with CVE-2012-2825 (RHSA-2012:1265) as the patch was included in our packages as noted in the changelog. - CVE-2012-2825 requires an extra patch on 1.1.17 Statement: Not vulnerable. This issue was corrected in Red Hat Enterprise Linux 5 via RHSA-2012:1265. It did not affect Red Hat Enterprise Linux 6. External References: https://rhn.redhat.com/errata/RHSA-2012-1265.html