oss-sec mailing list archives
CVE request: libxslt xsltStylePreCompute() type confusion DoS
From: Stefan Cornelius <scorneli () redhat com>
Date: Tue, 27 Oct 2015 13:48:38 +0100
Hi, A type confusion error within the libxslt "xsltStylePreCompute()" function in preproc.c can lead to a DoS. Confirmed in version 1.1.28, other versions may also be affected. Red Hat bug: https://bugzilla.redhat.com/show_bug.cgi?id=1257962 Proposed patch (afaik, not yet committed upstream, but I believe that it'll happen soon): https://bugzilla.redhat.com/attachment.cgi?id=1086465 Thanks and kind regards, -- Stefan Cornelius / Red Hat Product Security
Current thread:
- CVE request: libxslt xsltStylePreCompute() type confusion DoS Stefan Cornelius (Oct 27)
- Re: CVE request: libxslt xsltStylePreCompute() type confusion DoS cve-assign (Oct 28)
