CVE-2023-40403

NameCVE-2023-40403
DescriptionThe issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1108074

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libxslt (PTS)bullseye1.1.34-4+deb11u1vulnerable
bullseye (security)1.1.34-4+deb11u2vulnerable
bookworm, bookworm (security)1.1.35-1+deb12u1vulnerable
sid, trixie1.1.35-1.2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libxsltsource(unstable)(unfixed)unimportant1108074

Notes

https://gitlab.gnome.org/GNOME/libxslt/-/issues/94
Fixed by: https://gitlab.gnome.org/GNOME/libxslt/-/commit/82f6cbf8ca61b1f9e00dc04aa3b15d563e7bbc6d (v1.1.38)
Backports: https://gitlab.gnome.org/GNOME/libxslt/-/issues/94#note_1855467
Hardening to improve ASLR, not a security issue by itself

Search for package or bug name: Reporting problems