Google Project Zero exposes security flaw in libxslt library used in GNOME applications

News Archive
0 Replies 483 Views

Gandalf_The_Grey

Level 86
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Forum Veteran
libxslt is based on the libxml2 library, and was built as an open-source software (OSS) under the GNOME project. It is used to transform XML documents using Extensible Stylesheet Language Transformations (XSLT). Example use-cases include transforming XML documents into HTML in web browsers, rendering XML content in office applications, and more. Many applications utilize this library including implementations in PHP and Python on the web, Doxygen, Gnumeric, and GNOME Help System, among others.
Interestingly, GNOME has also been tracking this bug since Project Zero's report and has made this particular item publicly visible too following the security team's deadline exceeding. A quick read of the thread indicates that while some people are working on a fix, it is not complete yet due to the patch breaking some other components in the process. The community has also noted that since libxslt has no active maintainer (the original creator Daniel Veillard apparently hasn't responded in months), it's unlikely that an upstream patch will ever be released, and it's very possible that downstream systems will have to "fend for themselves".
As such, the overall situation is a bit tricky. Google has disclosed the bug following the expiration of its 90-day deadline, the GNOME project has no complaint against this but is kind of helpless due to the lack of an active libxslt maintainer who can own the issue, and the bug itself is now public with proof-of-concept (PoC) code, which threat actors can potentially leverage for exploits.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top