Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Sun, 6 Nov 2016 21:35:24 +0100
From: Salvatore Bonaccorso <>
To: OSS Security Mailinglist <>
Cc: CVE Assignments MITRE <>
Subject: Clarification about CVE-2016-1841 for libxslt


CVE-2016-1841 is assigned for libxslt, and the CVE description from
MITRE states:

> libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5,
> tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers
> to execute arbitrary code or cause a denial of service (memory
> corruption) via a crafted web site. 

Following the references from Apple, this seems to be related to an
issue reported by Sebastian Apelt. Recent bug reports and commits
related to issues reported by SEbastian Apelt seem to be:

with corresponding upstream commit:

Is this CVE association correct?


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.