Insecure functionality In libxslt
Description
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.18 | 1.1.38-r1 | ||
alpine v3.19 | 1.1.39-r1 | ||
alpine v3.20 | 1.1.39-r2 | ||
alpine v3.21 | 1.1.42-r2 | ||
alpine v3.22 | 1.1.43-r0 | ||
debian 12 | 1.1.35-1+deb12u1 | ||
debian 13 | 1.1.35-1.2 | ||
debian 14 | 1.1.35-1.2 | ||
alpine v3.23 | 1.1.43-r0 | ||
rpm rhel8 | 0:1.1.32-6.1.el8_10 |
1-10 of 18
10
Aliases
1. 2. 3. 4. 5. 6. 7.