Lector de Feeds
MGASA-2025-0110 - Updated libxslt packages fix security vulnerabilities
Publication date: 22 Mar 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-55549 , CVE-2025-24855 Description xsltGetInheritedNsList in libxslt has a use-after-free issue related to exclusion of result prefixes (CVE-2024-55549). numbers.c in libxslt has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal (CVE-2025-24855). References
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-55549 , CVE-2025-24855 Description xsltGetInheritedNsList in libxslt has a use-after-free issue related to exclusion of result prefixes (CVE-2024-55549). numbers.c in libxslt has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal (CVE-2025-24855). References
- https://bugs.mageia.org/show_bug.cgi?id=34113
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/ZKCQGOW24ZBKSYCIKDUG4KKITEGCJKY2/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-55549
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24855
- libxslt-1.1.38-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2025-0109 - Updated expat packages fix security vulnerability
Publication date: 22 Mar 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-8176 Description Improper restriction of xml entity expansion depth in libexpat. (CVE-2024-8176) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-8176 Description Improper restriction of xml entity expansion depth in libexpat. (CVE-2024-8176) References
- https://bugs.mageia.org/show_bug.cgi?id=34111
- https://www.openwall.com/lists/oss-security/2025/03/14/5
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8176
- expat-2.7.0-1.mga9
Categorías: Actualizaciones de Seguridad
