GNOME.libxslt is vulnerable to Use-After-Free
78
High Risk
In libxslt versions before 1.1.43, a use-after-free vulnerability exists due to improper handling of the XPath context node during nested XPath evaluations. When the context node is modified but not restored, it leads to a use-after-free issue. This affects functions like xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
You are affected if you are using a version that falls within the vulnerable range.
GNOME.libxslt is vulnerable to Use-After-Free in versions 0.0.1 - 1.1.42.
Upgrade the GNOME.libxslt library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant