PublicDateAtUSN: 2015-11-17 Candidate: CVE-2015-7995 PublicDate: 2015-11-17 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7995 http://www.openwall.com/lists/oss-security/2015/10/27/10 https://ubuntu.com/security/notices/USN-3271-1 Description: The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue. Ubuntu-Description: Notes: sbeattie> reproducer in Red Hat bug Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=802971 https://bugzilla.redhat.com/show_bug.cgi?id=1257962 Priority: low Discovered-by: Assigned-to: CVSS: Patches_libxslt: upstream: https://git.gnome.org/browse/libxslt/commit/?id=7ca19df892ca22d9314e95d59ce2abdeff46b617 upstream_libxslt: released (1.1.29) precise_libxslt: released (1.1.26-8ubuntu1.4) trusty_libxslt: released (1.1.28-2ubuntu0.1) trusty/esm_libxslt: released (1.1.28-2ubuntu0.1) vivid_libxslt: ignored (reached end-of-life) vivid/stable-phone-overlay_libxslt: DNE vivid/ubuntu-core_libxslt: DNE wily_libxslt: ignored (reached end-of-life) xenial_libxslt: not-affected (1.1.28-2.1) esm-infra/xenial_libxslt: not-affected (1.1.28-2.1) yakkety_libxslt: not-affected (1.1.28-2.1) zesty_libxslt: not-affected (1.1.28-2.1) devel_libxslt: not-affected (1.1.28-2.1)