Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-24855

Опубликовано: 14 мар. 2025
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

A flaw was found in libxslt numbers.c. This vulnerability allows a use-after-free, potentially leading to memory corruption or code execution via nested XPath evaluations where an XPath context node can be modified but not restored.

Отчет

The use-after-free vulnerability in libxslt marked as a high severity rather than moderate due to its potential impact on system integrity and availability. This flaw arises during nested XPath evaluations where the context node can be modified without proper restoration, leading to use-after-free conditions. Exploitation of this vulnerability allows an attacker to execute arbitrary code, potentially causing significant disruptions or unauthorized actions within the affected system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libxsltOut of support scope
Red Hat Enterprise Linux 10libxsltFixedRHSA-2025:749613.05.2025
Red Hat Enterprise Linux 7 Extended Lifecycle SupportlibxsltFixedRHSA-2025:409823.04.2025
Red Hat Enterprise Linux 8libxsltFixedRHSA-2025:361507.04.2025
Red Hat Enterprise Linux 8libxsltFixedRHSA-2025:361507.04.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupportlibxsltFixedRHSA-2025:361907.04.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibxsltFixedRHSA-2025:362607.04.2025
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicelibxsltFixedRHSA-2025:362607.04.2025
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionslibxsltFixedRHSA-2025:362607.04.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportlibxsltFixedRHSA-2025:362507.04.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2352483libxslt: Use-After-Free in libxslt numbers.c

EPSS

Процентиль: 1%
0.00009
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

CVSS3: 7.8
nvd
3 месяца назад

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

CVSS3: 7.8
msrc
3 месяца назад

Описание отсутствует

CVSS3: 7.8
debian
3 месяца назад

numbers.c in libxslt before 1.1.43 has a use-after-free because, in ne ...

CVSS3: 7.8
github
3 месяца назад

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

EPSS

Процентиль: 1%
0.00009
Низкий

7.8 High

CVSS3