CVE-2008-2935
Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."
- Xmlsoft Libxslt
- = 1.1.8, 1.1.9, 1.1.10, 1.1.11, 1.1.12, 1.1.13, 1.1.14, 1.1.15, 1.1.16, 1.1.17, 1.1.18, 1.1.19, 1.1.20, 1.1.21, 1.1.22, 1.1.23, 1.1.24
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 12.8% (96th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2008-08-01
CVE-2008-2935 at NVD
2 known exploits for CVE-2008-2935
Proof-of-concept code and exploit modules indexed by Sploitus