Lector de Feeds

MGASA-2025-0110 - Updated libxslt packages fix security vulnerabilities

Mageia Security - 22 Marzo, 2025 - 18:53
Publication date: 22 Mar 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-55549 , CVE-2025-24855 Description xsltGetInheritedNsList in libxslt has a use-after-free issue related to exclusion of result prefixes (CVE-2024-55549). numbers.c in libxslt has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal (CVE-2025-24855). References SRPMS 9/core
  • libxslt-1.1.38-1.1.mga9

MGASA-2025-0109 - Updated expat packages fix security vulnerability

Mageia Security - 22 Marzo, 2025 - 18:53
Publication date: 22 Mar 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-8176 Description Improper restriction of xml entity expansion depth in libexpat. (CVE-2024-8176) References SRPMS 9/core
  • expat-2.7.0-1.mga9
Feed