The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.
AV:N/AC:M/Au:N/C:C/I:C/A:C
11/07/2007
by Sun
11 years ago
by Sun
11 years ago