Vulnerability Report

CVE-2012-6139

Title: Xmlsoft Libxslt Memory Corruption

Memory Corruption

Proof Of Concept

No public PoC currently indexed for CVE-2012-6139.

CWE Category NVD-CWE-noinfo
Published Date Apr 12, 2013
Modified Date Jun 16, 2026
Exploit Status Not Found
Score 5.0 CVSS v2.0
Exploit Probability (EPSS)
4.29%

Vulnerability Summary

CVE-2012-6139: libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c.

Impacted Vendors

Reference Links

http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102065.html http://lists.opensuse.org/opensuse-updates/2013-04/msg00020.html http://lists.opensuse.org/opensuse-updates/2013-04/msg00028.html http://secunia.com/advisories/52745 http://secunia.com/advisories/52805 http://secunia.com/advisories/52813 http://secunia.com/advisories/52884 http://www.debian.org/security/2013/dsa-2654 http://www.mandriva.com/security/advisories?name=MDVSA-2013:141 http://www.securitytracker.com/id/1028338 http://www.ubuntu.com/usn/USN-1784-1 http://xmlsoft.org/XSLT/news.html https://bugzilla.gnome.org/show_bug.cgi?id=685328 https://bugzilla.gnome.org/show_bug.cgi?id=685330 https://git.gnome.org/browse/libxslt/commit/?id=6c99c519d97e5fcbec7a9537d190efb442e4e833 https://git.gnome.org/browse/libxslt/commit/?id=dc11b6b379a882418093ecc8adf11f6166682e8d https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0107 https://www.suse.com/support/update/announcement/2013/suse-su-20131654-1.html https://www.suse.com/support/update/announcement/2013/suse-su-20131656-1.html http://lists.fedoraproject.org/pipermail/package-announce/2013-April/102065.html http://lists.opensuse.org/opensuse-updates/2013-04/msg00020.html http://lists.opensuse.org/opensuse-updates/2013-04/msg00028.html http://secunia.com/advisories/52745 http://secunia.com/advisories/52805 http://secunia.com/advisories/52813 http://secunia.com/advisories/52884 http://www.debian.org/security/2013/dsa-2654 http://www.mandriva.com/security/advisories?name=MDVSA-2013:141 http://www.securitytracker.com/id/1028338 http://www.ubuntu.com/usn/USN-1784-1 http://xmlsoft.org/XSLT/news.html https://bugzilla.gnome.org/show_bug.cgi?id=685328 https://bugzilla.gnome.org/show_bug.cgi?id=685330 https://git.gnome.org/browse/libxslt/commit/?id=6c99c519d97e5fcbec7a9537d190efb442e4e833 https://git.gnome.org/browse/libxslt/commit/?id=dc11b6b379a882418093ecc8adf11f6166682e8d https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0107 https://www.suse.com/support/update/announcement/2013/suse-su-20131654-1.html https://www.suse.com/support/update/announcement/2013/suse-su-20131656-1.html
CVSS v2.0
Source Entity [email protected]
Severity MEDIUM
5.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:N/I:N/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2012-6139 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected Stack

No specific products linked.