Home / mailingsPDF  

[SECURITY] [DSA 5979-1] libxslt security update

Posted on 19 August 2025
Debian Security Advisory

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5979-1 security@debian.org
https://www.debian.org/security/ Aron Xu
August 19, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libxslt
CVE ID : CVE-2023-40403 CVE-2025-7424
Debian Bug : 1108074 1109123

Two vunlerabilities were found in libxslt, the XSLT 1.0 processing library,
which may lead to information disclosure and DoS attack.

CVE-2023-40403

Information disclosure with weak memory handling of generated-id()

CVE-2025-7424

Type confusion in xmlNode.psvi between stylesheet and source nodes,
which may allow an attacker to crash the application or corrupt memory.

For the oldstable distribution (bookworm), these problems have been fixed
in version 1.1.35-1+deb12u2.

For the stable distribution (trixie), these problems have been fixed in
version 1.1.35-1.2+deb13u1.

We recommend that you upgrade your libxslt packages.

For the detailed security status of libxslt please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libxslt

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

 

TOP