CVE-2012-2870
libxslt - several
EPSS 0.68%
Description
libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/pattern.c and (2) the xsltGenerateIdFunction function in libxslt/functions.c.
How to fix CVE-2012-2870
To remediate CVE-2012-2870, upgrade the affected package to a fixed version below.
- Debian/libxslt—upgrade to 1.1.26-14 or later
- —upgrade to 1.1.26-6+squeeze2 or later
Is CVE-2012-2870 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.1.26-14
- from 0, < 1.1.26-6+squeeze2