Debian Security Advisory
DSA-5216-1 libxslt -- security update
- Date Reported:
- 24 Aug 2022
- Affected Packages:
- libxslt
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2021-30560.
- More information:
-
Nick Wellnhofer discovered that the xsltApplyTemplates function in libxslt, an XSLT processing runtime library, is prone to a use-after-free flaw, resulting in a denial of service, or potentially the execution of arbitrary code if a specially crafted file is processed.
For the stable distribution (bullseye), this problem has been fixed in version 1.1.34-4+deb11u1.
We recommend that you upgrade your libxslt packages.
For the detailed security status of libxslt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libxslt