CVE-2019-11068

Publication date

2019-04-10 19:38:18

Family

mitre

State

PUBLISHED

Description

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.