it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Aron Xu <aron AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5979-1] libxslt security update
- Date: Tue, 19 Aug 2025 07:37:56 +0000
- Authentication-results: lists.piratenpartei.de; dkim=none; spf=none (lists.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/E1uoGuq-0016Ys-1l AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=SDS91Ly6klngxL7V8h/tezipl40WWh54+k77AXKdqO4=; b=es +AHlPI4fOQLei+ugHGPb+RRkiwFBWaXypEpbY+BlfXTmq9xVhWf+sOY5GIPYQQfrMCbFYkAtWqEgs eEIjffE6YtJXFffT8P0xdDUV75DrTZTZPk2t0ERYq+/JPtd4wl/juzxsPz5jdVKYB1lzfnF3Dnj2f Z6ClCWL3P41xdFVgdJjJuptg199PH7eGJt3JuEYU/N/5jt+s4828xw/ltEXEpwLbNsbYDveLfHHwh GExUb52YNBvURsb/rSWGi3dsENWYTMAdHaU8ubjGjLZU4iB7J82SROPEiIs2kdHT0rdlQvgoISyAS 8xNyhhThXojThPIdzPLTbyX0S6O5Nh6g==;
- Old-return-path: <aron AT seger.debian.org>
- Priority: urgent
- Resent-date: Tue, 19 Aug 2025 07:38:22 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <ja208CEzh4G.A.MdAN.unCpoB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5979-1 security AT debian.org
https://www.debian.org/security/ Aron Xu
August 19, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : libxslt
CVE ID : CVE-2023-40403 CVE-2025-7424
Debian Bug : 1108074 1109123
Two vunlerabilities were found in libxslt, the XSLT 1.0 processing library,
which may lead to information disclosure and DoS attack.
CVE-2023-40403
Information disclosure with weak memory handling of generated-id()
CVE-2025-7424
Type confusion in xmlNode.psvi between stylesheet and source nodes,
which may allow an attacker to crash the application or corrupt memory.
For the oldstable distribution (bookworm), these problems have been fixed
in version 1.1.35-1+deb12u2.
For the stable distribution (trixie), these problems have been fixed in
version 1.1.35-1.2+deb13u1.
We recommend that you upgrade your libxslt packages.
For the detailed security status of libxslt please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libxslt
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCAAdFiEEBLHAyuu1xqoC2aJ5NP8o68vMTMgFAmikJswACgkQNP8o68vM
TMi/LggAjynmD8VLzKTfHtqyOKoF3i/dh3dKIw+PysMKjsXYFgt3cQmg6YMK8C+I
FR9CcSndxhvZeS3wkrHSAvUGf6YsHuQ8uoF1FMk+IIGipMQ6G30dP2H2W2bFw4BW
MgX2odIdB5wC27pO/myDbCjBpGQxUC1XSpw4NdLtZcp/97rSsEaP+v+Pm32/nwca
mSfxipbe9xQSiEl4PnrVVr3Igxk/VaiEuyMao2uetueTPBHtHIX6YxyVoRRAr6Ba
KOMMR/+VfkCp9qENMexjaFECoPgT/XJGCTnY8KOeD6qrv4GHaIzUz8vho0HsWmiw
I7Fb9Y9R2Fgqr0xi36Td5aSGWRuV1g==
=U/6/
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5979-1] libxslt security update, Aron Xu, 19.08.2025
Archiv bereitgestellt durch MHonArc 2.6.19+.