libxslt 1.1.x - RC4 Encryption and Decryption functions Buffer Overflow

Author: Chris Evans
type: remote
platform: linux
port: 
date_added: 2008-07-31  
date_updated: 2014-03-12  
verified: 1  
codes: CVE-2008-2935;OSVDB-47544  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 32133.txt  
source: https://www.securityfocus.com/bid/30467/info

The 'libxslt' library is prone to a heap-based buffer-overflow vulnerability because the software fails to perform adequate boundary checks on user-supplied data.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user running an application that relies on the affected library. Failed exploit attempts will likely result in denial-of-service conditions.

This issue affects libxslt 1.1.8 to 1.1.24.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/32133.xsl