HomeXmlsoftCVE-2019-11068

CVE-2019-11068

CRITICAL
9.8CVSS
Published: 2019-04-10
Updated: 2024-11-21
AI Analysis

Description

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
NVD-CWE-noinfo

Metadata

Primary Vendor
XMLSOFT
Published
4/10/2019
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

xmlsoft : libxsltcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxdebian : debian_linuxfedoraproject : fedorafedoraproject : fedoraoracle : jdknetapp : active_iq_unified_managernetapp : active_iq_unified_managernetapp : cloud_backupnetapp : e-series_santricity_management_plug-insnetapp : e-series_santricity_os_controllernetapp : e-series_santricity_storage_managernetapp : e-series_santricity_unified_managernetapp : e-series_santricity_web_services_proxynetapp : element_softwarenetapp : hci_management_nodenetapp : oncommand_insightnetapp : oncommand_workflow_automationnetapp : plug-in_for_symantec_netbackupnetapp : santricity_unified_managernetapp : snapmanagernetapp : snapmanagernetapp : solidfirenetapp : steelstore_cloud_integrated_storageopensuse : leapopensuse : leapopensuse : leap

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2019-11068 | CRITICAL Severity | CVEDatabase.com | CVEDatabase.com