oss-sec mailing list archives

Clarification about CVE-2016-1841 for libxslt


From: Salvatore Bonaccorso <carnil () debian org>
Date: Sun, 6 Nov 2016 21:35:24 +0100

Hi

CVE-2016-1841 is assigned for libxslt, and the CVE description from
MITRE states:

libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5,
tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers
to execute arbitrary code or cause a denial of service (memory
corruption) via a crafted web site. 

Following the references from Apple, this seems to be related to an
issue reported by Sebastian Apelt. Recent bug reports and commits
related to issues reported by SEbastian Apelt seem to be:

https://bugzilla.gnome.org/show_bug.cgi?id=758291

with corresponding upstream commit:

https://git.gnome.org/browse/libxslt/commit/?id=fc1ff481fd01e9a65a921c542fed68d8c965e8a3

Is this CVE association correct?

Regards,
Salvatore


Current thread: