CVE-2011-1202
Publication date 10 March 2011
Last updated 24 July 2024
Ubuntu priority
The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Not affected
|
|
11.04 natty |
Fixed 4.0.1+build1+nobinonly-0ubuntu0.11.04.1
|
|
10.10 maverick |
Fixed 3.6.17+build3+nobinonly-0ubuntu0.10.10.1
|
|
10.04 LTS lucid |
Fixed 3.6.17+build3+nobinonly-0ubuntu0.10.04.1
|
|
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life | |
libxslt | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Not affected
|
|
11.04 natty |
Fixed 1.1.26-6ubuntu0.1
|
|
10.10 maverick | Ignored end of life | |
10.04 LTS lucid |
Fixed 1.1.26-1ubuntu1.1
|
|
9.10 karmic | Ignored end of life | |
8.04 LTS hardy |
Fixed 1.1.22-1ubuntu1.3
|
|
6.06 LTS dapper | Ignored end of life | |
thunderbird | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Not affected
|
|
11.04 natty |
Fixed 3.1.10+build1+nobinonly-0ubuntu0.11.04.1
|
|
10.10 maverick |
Fixed 3.1.10+build1+nobinonly-0ubuntu0.10.10.1
|
|
10.04 LTS lucid |
Fixed 3.1.10+build1+nobinonly-0ubuntu0.10.04.1
|
|
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Not in release | |
xulrunner-1.9.2 | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty |
Fixed 1.9.2.17+build3+nobinonly-0ubuntu1
|
|
10.10 maverick |
Fixed 1.9.2.17+build3+nobinonly-0ubuntu0.10.10.1
|
|
10.04 LTS lucid |
Fixed 1.9.2.17+build3+nobinonly-0ubuntu0.10.04.1
|
|
9.10 karmic |
Fixed 1.9.2.17+build3+nobinonly-0ubuntu0.9.10.1
|
|
8.04 LTS hardy |
Fixed 1.9.2.17+build3+nobinonly-0ubuntu0.8.04.1
|
|
6.06 LTS dapper | Not in release |
References
Related Ubuntu Security Notices (USN)
- USN-1121-1
- Firefox vulnerabilities
- 30 April 2011
- USN-1123-1
- Xulrunner vulnerabilities
- 30 April 2011
- USN-1112-1
- Firefox and Xulrunner vulnerabilities
- 29 April 2011
- USN-1595-1
- libxslt vulnerabilities
- 4 October 2012
- USN-1122-1
- Thunderbird vulnerabilities
- 5 May 2011
- USN-1122-2
- Thunderbird vulnerabilities
- 5 May 2011