Beveiligingsadvies

CVE-2012-2870

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2012-08-31 19:00:00
Laatst bijgewerkt 2024-08-06 19:50:05
Toegewezen door Chrome
CVSS-score geen score
Status PUBLISHED

Beschrijving

libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.