Back

CRITICAL

libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL

Published Apr 10, 2019

Description

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

Affected products

Remediation

Red Hat statement

Red Hat OpenStack will consume fixes from the base Red Hat Enterprise Linux Operating System. Therefore the package provided by Red Hat OpenStack has been marked as will not fix.

Red Hat mitigation

This flaw only applies to applications compiled against libxml2 which use xsltCheckRead and xsltCheckWrite functions and/or allow users to load arbitrary URLs to be parsed via libxml2. In all other cases, applications are not vulnerable.

Metrics

Weaknesses (1)

References (29)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 10, 2019
Updated May 28, 2026
Reserved Apr 10, 2019
CISA Vulnrichment
Updated May 28, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 10, 2019
GHSA-QXCG-XJJG-66MJ