Two vunlerabilities were found in libxslt, the XSLT 1.0 processing library, which may lead to information disclosure and DoS attack.
CVE-2023-40403
Information disclosure with weak memory handling of generated-id()
CVE-2025-7424
Type confusion in xmlNode.psvi between stylesheet and source nodes, which may allow an attacker to crash the application or corrupt memory.
https://security-tracker.debian.org/tracker/DSA-5979-1
Continue reading...
CVE-2023-40403
Information disclosure with weak memory handling of generated-id()
CVE-2025-7424
Type confusion in xmlNode.psvi between stylesheet and source nodes, which may allow an attacker to crash the application or corrupt memory.
https://security-tracker.debian.org/tracker/DSA-5979-1
Continue reading...

