[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 514-1] libxslt security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : libxslt
Version        : 1.1.26-14.1+deb7u1
CVE ID         : CVE-2015-7995 CVE-2016-1683 CVE-2016-1684


Several vulnerabilities were found in libxslt.

CVE-2015-7995

    A missing type check could cause an application crash via a
    especially crafted file.

CVE-2016-1683

    An out of bounds heap access bug was found in libxslt.

CVE-2016-1684

    There was an integer overflow bug in libxslt that could lead to an
    application crash.

For Debian 7 "Wheezy", these problems have been fixed in version
1.1.26-14.1+deb7u1.

We recommend that you upgrade your libxslt packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJXXdkZAAoJEJ1GxIjkNoMCT/0P/itaoxR/G0h9ccno7XS1VzK2
f5RuBTZu19LiBVHv0RKP4NmSEyHAPsDdUOijYZ/KvXtpFoLM4cihRqJ4dQbLe4Gg
AW7IkXRYf4LqVZjuagCaYB5lvoP1DcSnqkUat8lVo88607E8M5RQSXfbQ3+H8hTZ
rk8Tjchj4KL27fU5M6HiaDX7kVa9W5x5LdhaSwHFRj30VtLZNx41kwbfaR9HvFWg
GfgTWKdHex3biEdkIxhFGaxVhhVButGjVUGo/PXabvbslDgD/8gndCpf6GDeRntW
US95jy8RZDLUXLP/dpck+QHD3nCHDa9xxp+QkEMGNkEnCoMTw7wsmYlAJOrtEuFX
L6pvYRWi9S0TTavILkW0c7DPqOQJJVfdvknsp4l6lqH96yB4uUDqZEI18nz4mlUU
mbRjnZ6vaYNiq8+94Zxpb/hYnxNJRG5l6LR6mbUOF3R5h4JQZOxdj4IqrHeI5z8D
a7wn2g9cGiKLarFMeB2gOe5ekrKOOWf4ZMLcrtm1UjeQX1BL6OVlWTJAYfmlyJv0
IxiBRIGQpBi6MbGyskRKRv0JJ9kH4x7B/XaIMghus3dAXssBRg1QkwH2d1uQWwuy
fIh2z6hscbpQEwzHPpGAbIWj/MOWOq2Wt1in0d2moDv7O6gIZd0ZiFqS00V/PcRJ
GDIB+fi5tsu2XgCx5WA/
=EuHR
-----END PGP SIGNATURE-----


Reply to: