[xml/sgml-pkgs] Bug#926895: libxslt: CVE-2019-11068
carnil at debian.org
Thu Apr 11 21:46:05 BST 2019
Tags: security upstream
The following vulnerability was published for libxslt.
| libxslt through 1.1.33 allows bypass of a protection mechanism because
| callers of xsltCheckRead and xsltCheckWrite permit access even upon
| receiving a -1 error code. xsltCheckRead can return -1 for a crafted
| URL that is not actually invalid and is subsequently loaded.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
Please adjust the affected versions in the BTS as needed.
More information about the debian-xml-sgml-pkgs