libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2019-04-10 13:29
Updated : 2020-08-24 10:37
NVD link : CVE-2019-11068
Mitre link : CVE-2019-11068
JSON object : View
CWE
Products Affected
debian
- debian_linux
xmlsoft
- libxslt
canonical
- ubuntu_linux