CVE-2011-1202

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-1202
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2011-1202.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2011-1202
Related
Published
2011-03-11T02:01:20Z
Modified
2024-06-30T12:01:22Z
Summary
[none]
Details

The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.

References

Affected packages

Debian:11 / libxslt

Package

Name
libxslt
Purl
pkg:deb/debian/libxslt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.26-7

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / libxslt

Package

Name
libxslt
Purl
pkg:deb/debian/libxslt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.26-7

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / libxslt

Package

Name
libxslt
Purl
pkg:deb/debian/libxslt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.26-7

Ecosystem specific

{
    "urgency": "low"
}