Univention Bugzilla – Bug 50864
libxslt: Multiple issues (4.4)
Last modified: 2020-03-11 14:41:55 CET
New Debian libxslt 1.1.29-2.1+deb9u2 fixes: This update addresses the following issue: * use after free in xsltCopyText in transform.c could lead to information disclosure (CVE-2019-18197)
--- mirror/ftp/4.4/unmaintained/4.4-2/source/libxslt_1.1.29-2.1+deb9u1.dsc +++ apt/ucs_4.4-0-errata4.4-3/source/libxslt_1.1.29-2.1+deb9u2.dsc @@ -1,3 +1,8 @@ +1.1.29-2.1+deb9u2 [Wed, 04 Dec 2019 15:41:16 +0100] Salvatore Bonaccorso <carnil@debian.org>: + + * Non-maintainer upload. + * Fix dangling pointer in xsltCopyText (CVE-2019-18197) (Closes: #942646) + 1.1.29-2.1+deb9u1 [Sat, 24 Aug 2019 14:04:13 +0200] Salvatore Bonaccorso <carnil@debian.org>: * Non-maintainer upload. <http://10.200.17.11/4.4-3/#7904089584905868140>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-3] e128a1d01d Bug #50864: libxslt 1.1.29-2.1+deb9u2 doc/errata/staging/libxslt.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) [4.4-3] 9826293cfb Bug #50864: libxslt 1.1.29-2.1+deb9u2 doc/errata/staging/libxslt.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<http://errata.software-univention.de/ucs/4.4/463.html>