-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmfcQiIFAwAAAAAACgkQZWnYVadEvpOS
jA/+MvMSpw52fag81fzH8RMTs7LrEn1+XxaGuf4JlVnLITmxToHV+1q49dvRDYoeNFDgxfrqLgik
kdANWyUnq3eEDwvoMb/H4NnBbdFsSInYkA2FyOeuUtYR1s/Eo5+E8YEG129TJZfhJuUNSoE+W1x3
VH+ArV1b91HdG30VyHDSU3COZoBXqb+dL0fz41iK/n5c5RIrdMPdWCgPpfs3GLQkG+GYW7Bv9ZlR
Wd8mSiUANsjKymAUehBMJDI1FO6msJo+6Dz4cI8MELxyAofILH5u+1NUt34aqcSP6OZl5ETvw1Ml
8QZN9aXEBddyTsNKng0XsuYMMaCBiUdgIf8pf34yvm2teDJnrg01VkzeTB0pf8q8yekfEB443f63
NK7IwxCJihhE6VIgIrStf6awTaASDTFcsNqiKd9uatK+lXx+rgPMok8+EM8yPsH2a0k2DqwVo9TR
i4s6Tlw40PPstfPHrGTKOXZvqp1xmdW+vMv4tqoWOIWtTRLm+x6mbL2ivSNBdGFS2ogoJhqnD5T3
BLuNSLMDjUCXiab6+N9ZYXcGDpKxJCwkz1l02fN9BOvgehMUNyfim8cbOXYYQZ5fj1FKYClf3GrC
AbSwdTN7gcla5dR8y9nT2HEuNgWnnTz4Metd2G3P6/GQ5AmHDzIORK2ZAJTiVrBzldtWFS+rJDIf
ACw=
=hP6C
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7361-1
March 20, 2025
libxslt vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Libxslt could be made to crash or run programs if it opened a specially
crafted file.
Software Description:
- libxslt: XSLT processing library
Details:
Ivan Fratric discovered that Libxslt incorrectly handled certain memory
operations when handling documents. A remote attacker could use this issue
to cause Libxslt to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libxslt1.1 1.1.39-0exp1ubuntu1.2
Ubuntu 24.04 LTS
libxslt1.1 1.1.39-0exp1ubuntu0.24.04.2
Ubuntu 22.04 LTS
libxslt1.1 1.1.34-4ubuntu0.22.04.3
Ubuntu 20.04 LTS
libxslt1.1 1.1.34-4ubuntu0.20.04.3
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7361-1
CVE-2025-24855
Package Information:
https://launchpad.net/ubuntu/+source/libxslt/1.1.39-0exp1ubuntu1.2
https://launchpad.net/ubuntu/+source/libxslt/1.1.39-0exp1ubuntu0.24.04.2
https://launchpad.net/ubuntu/+source/libxslt/1.1.34-4ubuntu0.22.04.3
https://launchpad.net/ubuntu/+source/libxslt/1.1.34-4ubuntu0.20.04.3
No comments:
Post a Comment