-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmfa7UIFAwAAAAAACgkQZWnYVadEvpNJ
CxAAjuZ0OhRCixkrvKQ53u0lU3f4X5WLBe1MZ617K9W4pk1CX3EsIuw8C4FFfIC+qGfkylBWQs1Z
8NC0LQEaCnvYVr46yH6k0tM1XFZNEfJzpopd07DSy98ckoHZTyq61U6KR0WzTEdZ5gZMCDH1SD3Q
JV2zm5YfeMj1g/6Fq4xo1TA+E+C2SoBoVDtut4GEMYaKrg1E18nt4SwnppO7nct+UKcaG4cogaZr
IMuhAZkbzzcxujMpGeCY/WzbgmNG44cpRZBN7iuRLFRgYEFjJe9ZafNQ/+lnmbJPVEIjmVzMBtCG
SZTJHkp3o1HHRASFpu4MKFAYc83S5DNoXPC+ZguitIAhaQH5ub+Qze6iTW+rTCnGjpzv8obS/bye
/rJ8edHaIWstKrnUe74N2A2o/opGCiXwderUZ8ck/h9NW7jI1T0yDPmOBjTjA288LI9EphX+v+0n
R+D+8ivgdexZf9kFhGZcqdViIQTEG3g8RX1Q/WI3O0YTnyaB/zlZLwyoQM1/CD3e/HkR8b/hNo4L
Whc4pA48uIBIDsQWh0wwitcA5yJMcaFN4fYoztF+xnY6Ohik+e0oOL6KRtGPLrVDirAarQvb1YvN
UkpmvQ/wudgmCvGRLXCqht+MsyTxg/CwpgCeVMheFGkTynVJWSVhawWSq9Xf9qHMprUOKIP5cyV4
Wd0=
=GrND
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7357-1
March 19, 2025
libxslt vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Libxslt could be made to crash or run programs if it opened a specially
crafted file.
Software Description:
- libxslt: XSLT processing library
Details:
Ivan Fratric discovered that Libxslt incorrectly handled certain memory
operations when handling documents. A remote attacker could use this issue
to cause Libxslt to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libxslt1.1 1.1.39-0exp1ubuntu1.1
Ubuntu 24.04 LTS
libxslt1.1 1.1.39-0exp1ubuntu0.24.04.1
Ubuntu 22.04 LTS
libxslt1.1 1.1.34-4ubuntu0.22.04.2
Ubuntu 20.04 LTS
libxslt1.1 1.1.34-4ubuntu0.20.04.2
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7357-1
CVE-2024-55549
Package Information:
https://launchpad.net/ubuntu/+source/libxslt/1.1.39-0exp1ubuntu1.1
https://launchpad.net/ubuntu/+source/libxslt/1.1.39-0exp1ubuntu0.24.04.1
https://launchpad.net/ubuntu/+source/libxslt/1.1.34-4ubuntu0.22.04.2
https://launchpad.net/ubuntu/+source/libxslt/1.1.34-4ubuntu0.20.04.2
No comments:
Post a Comment