Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201804-01 ] libxslt: Multiple vulnerabilities
Date: Wed, 04 Apr 2018 02:00:11
Message-Id: 20180404015224.GA30411@monkey
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201804-01
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: libxslt: Multiple vulnerabilities
9 Date: April 04, 2018
10 Bugs: #598204, #612194
11 ID: 201804-01
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities were discovered in libxslt, the worst of which
19 may allow a remote attacker to execute arbitrary code.
20
21 Background
22 ==========
23
24 libxslt is the XSLT C library developed for the GNOME project. XSLT is
25 an XML language to define transformations for XML.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 dev-libs/libxslt < 1.1.30 >= 1.1.30
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in libxslt. Please review
39 the CVE identifiers referenced below for details.
40
41 Impact
42 ======
43
44 A remote attacker, via a crafted HTML page, could possibly execute
45 arbitrary code, cause a Denial of Service condition or leak
46 information.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All libxslt users should upgrade to the latest version:
57
58 # emerge --sync
59 # emerge --ask --oneshot --verbose ">=dev-libs/libxslt-1.1.30"
60
61 References
62 ==========
63
64 [ 1 ] CVE-2016-4738
65 https://nvd.nist.gov/vuln/detail/CVE-2016-4738
66 [ 2 ] CVE-2017-5029
67 https://nvd.nist.gov/vuln/detail/CVE-2017-5029
68
69 Availability
70 ============
71
72 This GLSA and any updates to it are available for viewing at
73 the Gentoo Security Website:
74
75 https://security.gentoo.org/glsa/201804-01
76
77 Concerns?
78 =========
79
80 Security is a primary focus of Gentoo Linux and ensuring the
81 confidentiality and security of our users' machines is of utmost
82 importance to us. Any security concerns should be addressed to
83 security@g.o or alternatively, you may file a bug at
84 https://bugs.gentoo.org.
85
86 License
87 =======
88
89 Copyright 2018 Gentoo Foundation, Inc; referenced text
90 belongs to its owner(s).
91
92 The contents of this document are licensed under the
93 Creative Commons - Attribution / Share Alike license.
94
95 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature