REDHAT-BUG-2379228: High severity Gnome libxslt vulnerability
Type confusion in xmlNode.psvi between stylesheet and source nodes of libxslt. Due to sharing of the psvi field, data from the style-sheet context may be misinterpreted when used for source document nodes during XSLT transformations. As a result, parsing a crafted XSLT can corrupt memory or crash the application, and may allow remote code execution without authentication or user interaction, disrupting services that rely on libxslt.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2379228?
The severity of REDHAT-BUG-2379228 is critical due to potential memory corruption or application crashes.
How do I fix REDHAT-BUG-2379228?
To fix REDHAT-BUG-2379228, update libxslt to the latest patched version provided by your operating system vendor.
What causes REDHAT-BUG-2379228?
REDHAT-BUG-2379228 is caused by type confusion in the xmlNode.psvi field between stylesheet and source nodes during XSLT transformations.
What are the consequences of exploiting REDHAT-BUG-2379228?
Exploiting REDHAT-BUG-2379228 can lead to memory corruption, application instability, or complete crashes.
Which versions of libxslt are affected by REDHAT-BUG-2379228?
All versions of libxslt that share the psvi field between stylesheet and source nodes are potentially affected by REDHAT-BUG-2379228.