ELA-107-1 libxslt security update

fix authentication bypass vulnerability

2019-04-16
Packagelibxslt
Version1.1.26-14.1+deb7u4
Related CVEs CVE-2019-11068


It was discovered that there was a authentication bypass vulnerability in libxslt, a widely-used library for transforming files from XML to other arbitrary format.

This vulnerability was caused by invalid handling of xsltCheckRead and xsltCheckWrite -1 error return value, handled as a success code. Remote attackers could leverage this vulnerability to bypass protection mechanisms and possibly cause unauthorized disclosure of information or modification.



For Debian 7 Wheezy, these problems have been fixed in version 1.1.26-14.1+deb7u4.

We recommend that you upgrade your libxslt packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.