------------------------------------------------------------------------- Debian LTS Advisory DLA-4309-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin September 25, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libxslt Version : 1.1.34-4+deb11u3 CVE ID : CVE-2023-40403 CVE-2025-7424 Debian Bug : 1108074 1109123 Two vulnerabilities were found in libxslt, an XSLT 1.0 processing library, which could lead to to denial of service or information disclosure. CVE-2023-40403 It was discovered that the generate-id() function could return deterministic values and could leak the memory layout of different XML objects, which might lead to information disclosure. CVE-2025-7424 Ivan Fratric discovered a type confusion vulnerability in xmlNode.psvi between stylesheet and source nodes. which could lead to application crash. For Debian 11 bullseye, these problems have been fixed in version 1.1.34-4+deb11u3. We recommend that you upgrade your libxslt packages. For the detailed security status of libxslt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libxslt Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment:
signature.asc
Description: PGP signature