Описание
Security update for libxslt
This update for libxslt fixes the following issues:
- CVE-2019-11068: Fixed a protection mechanism bypass where callers of xsltCheckRead() and xsltCheckWrite() would permit access upon receiving an error (bsc#1132160).
This update was imported from the SUSE:SLE-12:Update update project.
Список пакетов
openSUSE Leap 42.3
libxslt-1.1.28-13.3.1
libxslt-devel-1.1.28-13.3.1
libxslt-devel-32bit-1.1.28-13.3.1
libxslt-python-1.1.28-13.3.1
libxslt-tools-1.1.28-13.3.1
libxslt1-1.1.28-13.3.1
libxslt1-32bit-1.1.28-13.3.1
Ссылки
- E-Mail link for openSUSE-SU-2019:1430-1
- SUSE Security Ratings
Описание
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Затронутые продукты
openSUSE Leap 42.3:libxslt-1.1.28-13.3.1
openSUSE Leap 42.3:libxslt-devel-1.1.28-13.3.1
openSUSE Leap 42.3:libxslt-devel-32bit-1.1.28-13.3.1
openSUSE Leap 42.3:libxslt-python-1.1.28-13.3.1
Ссылки
- CVE-2019-11068
- SUSE Bug 1132160
- SUSE Bug 1154212