Oval Definition:oval:org.cisecurity:def:1442
Revision Date:2016-12-23Version:6
Title:DSA-3709-1 -- libxslt -- security update
Description:Nick Wellnhofer discovered that the xsltFormatNumberConversion function in libxslt, an XSLT processing runtime library, does not properly check for a zero byte terminating the pattern string. This flaw can be exploited to leak a couple of bytes after the buffer that holds the pattern string.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2016-4738
DSA-3709-1
Platform(s):Debian 8
Product(s):libxslt
Definition Synopsis
  • Debian 8 is installed
  • AND libxslt is earlier than 0:1.1.28-2+deb8u2
  • BACK