CVE-2025-24855
14.03.2025, 02:15
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.Enginsight
| Vendor | Product | Version |
|---|---|---|
| xmlsoft | libxslt | 𝑥 < 1.1.43 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libxslt |
|
Common Weakness Enumeration