GNOME.libxslt is vulnerable to Use-After-Free
78
High Risk
In libxslt versions before 1.1.43, a use-after-free vulnerability exists due to improper handling of the XPath context node during nested XPath evaluations. When the context node is modified but not restored, it leads to a use-after-free issue. This affects functions like xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
You are affected if you are using a version that falls within the vulnerable range.
GNOME.libxslt is vulnerable to Use-After-Free in versions 0.0.1 - 1.1.42.
Upgrade the GNOME.libxslt library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant