This script is Copyright (C) 2012 Tenable Network Security, Inc.
The remote Scientific Linux host is missing one or more security
A flaw was found in the way xmlsec1 handled XML files that contain an
XSLT transformation specification. A specially-crafted XML file could
cause xmlsec1 to create or overwrite an arbitrary file while
performing the verification of a file's digital signature.
After installing the update, all running applications that use the
xmlsec1 library must be restarted for the update to take effect.
See also :
Update the affected packages.
Risk factor :
Medium / CVSS Base Score : 5.1
Family: Scientific Linux Local Security Checks
Nessus Plugin ID: 61032 ()
CVE ID: CVE-2011-1425