Logo
vulnerabilityCVE-2023-40403
Name
CVE-2023-40403
Source
NVD ( link)Debian ( link)
Description
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information.
CWEs
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libxslt
Patched

Vulnerability Ratings#


6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.1.45
Not Affected
buildroot
master
1.1.45
Not Affected
openwrt
master
1.1.42-r1
Not Affected
openwrt
openwrt-25.12
1.1.42-r1
Not Affected
yocto
master
1.1.45
Not Affected
yocto
scarthgap
1.1.43
Not Affected

Resolved with patches#


libxslt (yocto:kirkstone)

#
Title
Author
Resolve
1
Clean up attributes in source doc
Nick Wellnhofer <wellnhofer@aevum.de>
CVE-2023-40403
2
Make generate-id() deterministic
Nick Wellnhofer <wellnhofer@aevum.de>
CVE-2023-40403
3
Infrastructure to store extra data in source nodes
Nick Wellnhofer <wellnhofer@aevum.de>
CVE-2023-40403
4
Store RVT ownership in 'compression' member
Nick Wellnhofer <wellnhofer@aevum.de>
CVE-2023-40403
5
Store key status of source nodes as bit flag
Nick Wellnhofer <wellnhofer@aevum.de>
CVE-2023-40403