Lucene search

K
amazonAmazonALAS-2020-1464
HistoryDec 16, 2020 - 8:31 p.m.

Medium: libxslt

2020-12-1620:31:00
alas.aws.amazon.com
17

0.008 Low

EPSS

Percentile

81.7%

Issue Overview:

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded. (CVE-2019-11068 __)

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn’t reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed. (CVE-2019-18197 __)

Affected Packages:

libxslt

Issue Correction:
Run yum update libxslt to update your system.

New Packages:

i686:  
    libxslt-debuginfo-1.1.28-6.15.amzn1.i686  
    libxslt-1.1.28-6.15.amzn1.i686  
    libxslt-python26-1.1.28-6.15.amzn1.i686  
    libxslt-devel-1.1.28-6.15.amzn1.i686  
    libxslt-python27-1.1.28-6.15.amzn1.i686  
  
src:  
    libxslt-1.1.28-6.15.amzn1.src  
  
x86_64:  
    libxslt-1.1.28-6.15.amzn1.x86_64  
    libxslt-debuginfo-1.1.28-6.15.amzn1.x86_64  
    libxslt-python26-1.1.28-6.15.amzn1.x86_64  
    libxslt-python27-1.1.28-6.15.amzn1.x86_64  
    libxslt-devel-1.1.28-6.15.amzn1.x86_64