A flaw was found in libxslt, the XSLT 1.0 processing library, where the attribute type, atype, flags are modified in a way that corrupts internal memory management. This is addressed by adding guards in libxml2, the GNOME XML library, preventing the heap use-after-free from happening.
https://security-tracker.debian.org/tracker/DSA-5990-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-5990-1
Continue reading...

