Sploitus

CVE-2008-2935

2 known exploits for CVE-2008-2935

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

Affected products
Red Hat, Libxslt
Xmlsoft Libxslt
= 1.1.8, 1.1.9, 1.1.10, 1.1.11, 1.1.12, 1.1.13, 1.1.14, 1.1.15, 1.1.16, 1.1.17, 1.1.18, 1.1.19, 1.1.20, 1.1.21, 1.1.22, 1.1.23, 1.1.24
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
12.8% (96th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2008-08-01
CVE-2008-2935 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2008-2935

Proof-of-concept code and exploit modules indexed by Sploitus