Re: libxslt: some CVEs not fixed in debian buster

2022-07-28 Thread David Bremner
Akira Shibakawa writes: > CVE-2019-5815 and CVE-2021-30560 are vulnerabilities of libxslt > included in chromium source code as third-party code. > And not only chromium but also libxslt upstream has already fixed them. > https://gitlab.gnome.org/GNOME/libxslt/-/commit/08b62c258 > https://gitlab.

libxslt: some CVEs not fixed in debian buster

2022-07-27 Thread Akira Shibakawa
Hi, CVE-2019-5815 and CVE-2021-30560 are vulnerabilities of libxslt included in chromium source code as third-party code. And not only chromium but also libxslt upstream has already fixed them. https://gitlab.gnome.org/GNOME/libxslt/-/commit/08b62c258 https://gitlab.gnome.org/GNOME/libxslt/-/commit