| PROBLEM: | It was discovered that a buffer overflow in the RC4 functions of libexslt may lead to the execution of arbitrary code. |
| PLATFORM: | Debian GNU/Linux 4.0 (etch) |
| DAMAGE: | Execution of arbitrary code. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. May lead to the execution of arbitrary code. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
7.5 6.2 (AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-363.shtml |
| ORIGINAL BULLETIN: | http://www.debian.org/security/2008/dsa-1624 |
| CVE: | CVE-2008-2935 |
[***** Start Debian Security Advisory DSA-1624-1 *****]
Chris Evans discovered that a buffer overflow in the RC4 functions of libexslt may lead to the execution of arbitrary code.
For the stable distribution (etch), this problem has been fixed in version 1.1.19-3.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your libxslt packages.
MD5 checksums of the listed files are available in the original advisory.
[***** End Debian Security Advisory DSA-1624-1 *****]
Voice: +1 866-941-2472 (7 x 24)
E-mail: doecirc@doecirc.energy.gov
World Wide Web: http://www.doecirc.energy.gov/