xmlsec1: arbitrary file creation when verifying signatures
Published Apr 3, 2011
5.1
MEDIUMCVSS 2.0
EPSS 8.06%
Description
xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.
Affected products
No data.
- ≤ 1.2.16
- 0.0.1
- 0.0.2
- 0.0.2a
- 0.0.3
- 0.0.4
- 0.0.5
- 0.0.6
- 0.0.7
- 0.0.8
- 0.0.9
- 0.0.10
- 0.0.11
- 0.0.12
- 0.0.13
- 0.0.14
- 0.0.15
- 0.1.0
- 0.1.1
- 1.0.0
- 1.0.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.1.0
- 1.1.1
- 1.1.2
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.2.7
- 1.2.8
- 1.2.9
- 1.2.10
- 1.2.11
- 1.2.13
- 1.2.14
- 1.2.15
- n/a
No data.
Red Hat Enterprise Linux 4
xmlsec1-0:1.2.6-3.2
Fixed · RHSA-2011:0486
Red Hat Enterprise Linux 5
xmlsec1-0:1.2.9-8.1.2
Fixed · RHSA-2011:0486
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | xmlsec1-0:1.2.6-3.2 | Fixed | RHSA-2011:0486 |
| Red Hat Enterprise Linux 5 | xmlsec1-0:1.2.9-8.1.2 | Fixed | RHSA-2011:0486 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.06% (0.08057) | 94.63th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.06% (0.08057) | 94.04th | v5 (v2026.06.15) |
| May 8, 2025 | 9.61% (0.09609) | 92.43th | v4 (v2025.03.14) |
| Mar 30, 2025 | 10.69% (0.10693) | 92.63th | v4 (v2025.03.14) |
| Mar 29, 2025 | 21.22% (0.21224) | 92.94th | v4 (v2025.03.14) |
| Mar 19, 2025 | 10.69% (0.10693) | 92.38th | v4 (v2025.03.14) |
| Mar 17, 2025 | 8.17% (0.08167) | 91.56th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.24% (0.01239) | 86.07th | v3 (v2023.03.01) |
| May 2, 2024 | 1.24% (0.01239) | 85.31th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.24% (0.01239) | 83.31th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.93% (0.03932) | 85.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.93% (0.03932) | 84.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.93% (0.03932) | 67.70th | v2 (v2022.01.01) |
References (22)
- http://git.gnome.org/browse/xmlsec/commit/?id=2d5eddcc4163ea050cf3a3a1a25452bb5124f780 x_refsource_CONFIRMPatch
- http://git.gnome.org/browse/xmlsec/commit/?id=35eaacde6093d6711339754fc2146341b8b9f5fa x_refsource_CONFIRMPatch
- http://secunia.com/advisories/43920 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/44167 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/44423 third-party-advisoryx_refsource_SECUNIA
- http://trac.webkit.org/changeset/79159 x_refsource_CONFIRM
- http://www.aleksey.com/pipermail/xmlsec/2011/009120.html mailing-listx_refsource_MLISTPatch
- http://www.debian.org/security/2011/dsa-2219 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:063 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2011-0486.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/47135 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1025284 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2011/0855 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0858 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/1010 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/1172 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2011-1425 Vendor Advisory
- https://bugs.webkit.org/show_bug.cgi?id=52688 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=692133 x_refsource_CONFIRMPatchIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66506 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2011-1425
- https://www.cve.org/CVERecord?id=CVE-2011-1425
Change history (0)
No recorded changes yet.