Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-3107

Опубликовано: 24 мар. 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-3107: libxslt security update (IMPORTANT)

[1.1.34-9.0.1.el9_5.1]

  • Added libxslt-oracle-enterprise.patch and replaced doc/redhat.gif in tarball

[1.1.34-9.1]

  • Fix CVE-2025-24855 (RHEL-83501)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

libxslt

1.1.34-9.0.1.el9_5.1

libxslt-devel

1.1.34-9.0.1.el9_5.1

Oracle Linux x86_64

libxslt

1.1.34-9.0.1.el9_5.1

libxslt-devel

1.1.34-9.0.1.el9_5.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

CVSS3: 7.8
redhat
3 месяца назад

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

CVSS3: 7.8
nvd
3 месяца назад

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

CVSS3: 7.8
msrc
3 месяца назад

Описание отсутствует

CVSS3: 7.8
debian
3 месяца назад

numbers.c in libxslt before 1.1.43 has a use-after-free because, in ne ...