Executive Summary

Informations
Name MDVSA-2013:141 First vendor Publication 2013-04-11
Vendor Mandriva Last vendor Modification 2013-04-11
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Updated libxslt packages fix security vulnerability:

Nicholas Gregoire discovered that libxslt incorrectly handled certain empty values. If a user or automated system were tricked into processing a specially crafted XSLT document, a remote attacker could cause libxslt to crash, causing a denial of service (CVE-2012-6139).

Original Source

Url : http://www.mandriva.com/security/advisories?name=MDVSA-2013:141

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:18038
 
Oval ID: oval:org.mitre.oval:def:18038
Title: USN-1784-1 -- libxslt vulnerability
Description: Applications using libxslt could be made to crash if they processed a specially crafted file.
Family: unix Class: patch
Reference(s): USN-1784-1
CVE-2012-6139
Version: 7
Platform(s): Ubuntu 12.10
Ubuntu 12.04
Ubuntu 11.10
Ubuntu 10.04
Ubuntu 8.04
Product(s): libxslt
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:20102
 
Oval ID: oval:org.mitre.oval:def:20102
Title: DSA-2654-1 libxslt - denial of service
Description: Nicolas Gregoire discovered that libxslt, an XSLT processing runtime library, is prone to denial of service vulnerabilities via crafted XSL stylesheets.
Family: unix Class: patch
Reference(s): DSA-2654-1
CVE-2012-6139
Version: 5
Platform(s): Debian GNU/Linux 6.0
Debian GNU/kFreeBSD 6.0
Product(s): libxslt
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:25828
 
Oval ID: oval:org.mitre.oval:def:25828
Title: SUSE-SU-2013:0727-1 -- Security update for libxslt
Description: libxslt has been updated to fix two denial of service issues via crashes by NULL pointer dereference on attacker supplied XSLT scripts (CVE-2012-6139).
Family: unix Class: patch
Reference(s): SUSE-SU-2013:0727-1
CVE-2012-6139
Version: 3
Platform(s): SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Server 10
SUSE Linux Enterprise Desktop 11
SUSE Linux Enterprise Desktop 10
Product(s): libxslt
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 79
Os 4

Nessus® Vulnerability Scanner

Date Description
2015-01-19 Name : The remote Solaris system is missing a security patch for third-party software.
File : solaris11_libxslt_20140114.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2013-289.nasl - Type : ACT_GATHER_INFO
2014-01-12 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201401-07.nasl - Type : ACT_GATHER_INFO
2013-11-12 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_libxslt-131106.nasl - Type : ACT_GATHER_INFO
2013-05-01 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_libxslt-130327.nasl - Type : ACT_GATHER_INFO
2013-05-01 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_libxslt-8534.nasl - Type : ACT_GATHER_INFO
2013-04-20 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2013-141.nasl - Type : ACT_GATHER_INFO
2013-04-18 Name : The remote Fedora host is missing a security update.
File : fedora_2013-4507.nasl - Type : ACT_GATHER_INFO
2013-04-04 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2654.nasl - Type : ACT_GATHER_INFO
2013-04-03 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1784-1.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2014-02-17 11:43:45
  • Multiple Updates
2013-04-15 21:20:21
  • Multiple Updates
2013-04-13 13:20:27
  • Multiple Updates
2013-04-11 17:18:32
  • First insertion