CVE-2008-1767
Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.
- Redhat Desktop
- = 3
- Redhat Enterprise Linux
- = 2.1, 3.0, 4.0, 5.0
- Redhat Enterprise Linux Desktop
- = 4, 5
- Redhat Enterprise Linux Desktop Workstation
- = 5
- Redhat Linux Advanced Workstation
- = 2.1
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 12.8% (96th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2008-05-23
CVE-2008-1767 at NVD
2 known exploits for CVE-2008-1767
Proof-of-concept code and exploit modules indexed by Sploitus