Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 30: FEDORA-2019-e21c77ffae Moderate: libxslt Security Bypass

fedora
Calendar Grey June 13, 2019
Dist Fedora Esm H88
Essential protection enhancement for Fedora 30 addressing libxslt vulnerabilities and maintaining system stability with release 1.1.33.
Update to 1.1.33 and fix CVE-2019-11068

Summary

This C library allows to transform XML files into other XML files

(or HTML, text, ...) using the standard XSLT stylesheet transformation

mechanism. To use it you need to have a version of libxml2 >= 2.6.27

installed. The xsltproc command is a command line interface to the XSLT engine

Update to 1.1.33 and fix CVE-2019-11068

* Fri Jun 7 2019 David King - 1.1.33-1

- Update to 1.1.33

- Fix CVE-2019-11068 (#1709698)

* Mon May 6 2019 Artem S. Tashkinov - 1.1.32-5

- Apply an extra patch to fix PR1467435 and make it possible to coinstall

libxslt-devel.x64 and libxslt-devel.i686

[ 1 ] Bug #1709698 - CVE-2019-11068 libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1709698

su -c 'dnf upgrade --advisory FEDORA-2019-e21c77ffae' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 1.1.33
Release: 1.fc30
URL:
Summary: Library providing the Gnome XSLT engine

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here