Vulnerability Bulletins

DSA-3709 libxslt - security update

   
Affected software Debian
 
Nick Wellnhofer discovered that the xsltFormatNumberConversion functionin libxslt, an XSLT processing runtime library, does not properly checkfor a zero byte terminating the pattern string. This flaw can beexploited to leak a couple of bytes after the buffer that holds thepattern string.

More info:

https://www.debian.org/security/2016/dsa-3709