GNOME.libxslt is vulnerable to Type Confusion
75
High Risk
When document() loads the stylesheet that is already running, libxslt uses that stylesheet document as the source document. Stylesheet nodes and source nodes share the psvi field, so a stylesheet that calls document() on itself makes the transform read psvi as the wrong type and can corrupt memory or crash the process. The fix copies the stylesheet document and clears psvi on the copy before reuse.
You are affected if you are using a version that falls within the vulnerable range and you transform untrusted XSLT that calls document() on the stylesheet itself.
GNOME.libxslt is vulnerable to Type Confusion in versions 0.0.1 - 1.1.43.
Upgrade the GNOME.libxslt library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.