Bug 1027360 (CVE-2013-4520) - CVE-2013-4520 libxslt: DoS when reading unexpected DTD nodes in XSLT in versions prior to 1.1.25
Summary: CVE-2013-4520 libxslt: DoS when reading unexpected DTD nodes in XSLT in versi...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2013-4520
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-11-06 16:11 UTC by Vincent Danen
Modified: 2021-02-17 07:12 UTC (History)
2 users (show)

Fixed In Version: libxslt 1.1.25
Clone Of:
Environment:
Last Closed: 2013-11-06 16:13:00 UTC
Embargoed:


Attachments (Terms of Use)

Description Vincent Danen 2013-11-06 16:11:11 UTC
It was reported that the fix for CVE-2012-2825 was incomplete for versions of libxslt prior to 1.1.25.  The same flaw is still present in those older versions of libxslt without this additional fix:

https://gitorious.org/libxslt/libxslt/commit/7089a62b8f133b42a2981cf1f920a8b3fe9a8caa

This never affected the versions of libxslt as provided with Red Hat Enterprise Linux 6 or Fedora.  It was also corrected in Red Hat Enterprise Linux 5's libxslt as fixed with CVE-2012-2825 (RHSA-2012:1265) as the patch was included in our packages as noted in the changelog.

- CVE-2012-2825 requires an extra patch on 1.1.17


Statement:

Not vulnerable.  This issue was corrected in Red Hat Enterprise Linux 5 via RHSA-2012:1265.  It did not affect Red Hat Enterprise Linux 6.


External References:

https://rhn.redhat.com/errata/RHSA-2012-1265.html


Note You need to log in before you can comment on or make changes to this bug.