Ubuntu Security Notice USN-3271-1
27th April, 2017
libxslt vulnerabilities
A security issue affects these releases of Ubuntu and its
derivatives:
- Ubuntu 17.04
- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary
Several security issues were fixed in Libxslt.
Software description
- libxslt
- XSLT processing library
Details
Holger Fuhrmannek discovered an integer overflow in the
xsltAddTextString() function in Libxslt. An attacker could use
this to craft a malicious document that, when opened, could cause a
denial of service (application crash) or possible execute arbitrary
code. ()
Sebastian Apelt discovered that a use-after-error existed in the
xsltDocumentFunctionLoadDocument() function in Libxslt. An attacker
could use this to craft a malicious document that, when opened,
could cause a denial of service (application crash) or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 14.04 LTS, and Ubuntu 12.04 LTS. ()
Nicolas Gregoire discovered the Libxslt mishandled the 'i' and 'a'
format tokens for xsl:number data. An attacker could use this to
craft a malicious document that, when opened, could cause a denial of
service (application crash). This issue only affected Ubuntu 16.04 LTS,
Ubuntu 14.04 LTS, and Ubuntu 12.04 LTS. ()
Update instructions
The problem can be corrected by updating your system to the following
package version:
- Ubuntu 17.04:
- Ubuntu 16.10:
- Ubuntu 16.04 LTS:
- Ubuntu 14.04 LTS:
- Ubuntu 12.04 LTS:
To update your system, please follow these instructions:
,
,
,
CVE-2017-5029
SOCIAL SHARE CARD GENERATOR