Debian Security Advisory 3709-1

Discussion in 'News Aggregator' started by Packet Storm, 11 Nov 2016.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 3709-1 - Nick Wellnhofer discovered that the xsltFormatNumberConversion function in libxslt, an XSLT processing runtime library, does not properly check for a zero byte terminating the pattern string. This flaw can be exploited to leak a couple of bytes after the buffer that holds the pattern string.

    Continue reading...
     

Share This Page

Loading...