• Bug#1109123: libxslt: CVE-2025-7424

    From Salvatore Bonaccorso@21:1/5 to All on Fri Jul 11 21:20:01 2025
    Source: libxslt
    Version: 1.1.35-1.2
    Severity: important
    Tags: security upstream
    Forwarded: https://gitlab.gnome.org/GNOME/libxslt/-/issues/139
    X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

    Hi,

    The following vulnerability was published for libxslt.

    CVE-2025-7424[0]:
    | A flaw was found in the libxslt library. The same memory field,
    | psvi, is used for both stylesheet and input data, which can lead to
    | type confusion during XML transformations. This vulnerability allows
    | an attacker to crash the application or corrupt memory. In some
    | cases, it may lead to denial of service or unexpected behavior.


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-7424
    https://www.cve.org/CVERecord?id=CVE-2025-7424
    [1] https://gitlab.gnome.org/GNOME/libxslt/-/issues/139

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)