Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20161106203524.hkl2ketyczothiuk@eldamar.local>
Date: Sun, 6 Nov 2016 21:35:24 +0100
From: Salvatore Bonaccorso <carnil@...ian.org>
To: OSS Security Mailinglist <oss-security@...ts.openwall.com>
Cc: CVE Assignments MITRE <cve-assign@...re.org>
Subject: Clarification about CVE-2016-1841 for libxslt

Hi

CVE-2016-1841 is assigned for libxslt, and the CVE description from
MITRE states:

> libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5,
> tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers
> to execute arbitrary code or cause a denial of service (memory
> corruption) via a crafted web site. 

Following the references from Apple, this seems to be related to an
issue reported by Sebastian Apelt. Recent bug reports and commits
related to issues reported by SEbastian Apelt seem to be:

https://bugzilla.gnome.org/show_bug.cgi?id=758291

with corresponding upstream commit:

https://git.gnome.org/browse/libxslt/commit/?id=fc1ff481fd01e9a65a921c542fed68d8c965e8a3

Is this CVE association correct?

Regards,
Salvatore

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.