Logo
componentlibxslt
Name
libxslt
Version
1.1.42-r
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:xmlsoft:libxslt:1.1.42:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
1.1.42-r1

Vulnerabilities#


Name
Analysis
Description
Exploitable
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
Exploitable
xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.