CVE-2012-2893
Publication date 26 September 2012
Last updated 24 July 2024
Ubuntu priority
Description
Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.
Status
Package | Ubuntu Release | Status |
---|---|---|
libxslt | ||
chromium-browser | ||
Notes
seth-arnold
confirmed Revision 154331 code exists in libxslt standalone package in 12.04 LTS
jdstrand
mdeslaur provided the update for libxslt
References
Related Ubuntu Security Notices (USN)
- USN-1595-1
- libxslt vulnerabilities
- 4 October 2012
Other references
- https://src.chromium.org/viewvc/chrome?view=rev&revision=154331
- https://chromiumcodereview.appspot.com/10919019
- http://git.chromium.org/gitweb/?p=chromium.git;a=commit;h=9a5da8e7d4b6f3454614b0331a51bf29c966f556
- https://code.google.com/p/chromium/issues/detail?id=144799
- http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html
- https://rhn.redhat.com/errata/RHSA-2012-1265.html
- https://www.cve.org/CVERecord?id=CVE-2012-2893