Articles / Debian: New libxslt package…

Debian: New libxslt packages fix execution of arbitrary code

It was discovered that libxslt, an XSLT processing runtime library, could be coerced into executing arbitrary code via a buffer overflow when an XSL style sheet file with a long XSLT "transformation match" condition triggered a large number of steps. Fixed packages are available from
Debian Security Advisory DSA-1589-1                                       Steve Kemp
May 28, 2008                
Package        : libxslt
Vulnerability  : buffer overflow
Problem type   : local
Debian-specific: no
CVE Id(s)      : CVE-2008-1767
Debian Bug     : 482664

It was discovered that libxslt, an XSLT processing runtime library,
could be coerced into executing arbitrary code via a buffer overflow
when an XSL style sheet file with a long XSLT "transformation match"
condition triggered a large number of steps.

For the stable distribution (etch), this problem has been fixed in version

For the unstable distribution (sid), this problem has been fixed in
version 1.1.24-1.

We recommend that you upgrade your libxslt package.

--------------------

Debian GNU/Linux 4.0 alias etch
---------------------------------------------------------------------------------
