Your submission was sent successfully! Close

CVE-2016-4608

Published: 22 July 2016

libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-4609, CVE-2016-4610, and CVE-2016-4612.

Priority

Medium

CVSS 3 base score: 9.8

Status

Package Release Status
libxslt
Launchpad, Ubuntu, Debian
precise
Released (1.1.26-8ubuntu1.4)
trusty
Released (1.1.28-2ubuntu0.1)
upstream Needs triage

wily Ignored
(reached end-of-life)
xenial
Released (1.1.28-2.1ubuntu0.1)
yakkety Not vulnerable
(1.1.29-1)
zesty Not vulnerable
(1.1.29-1)

Notes

AuthorNote
sbeattie
may be https://bugzilla.gnome.org/show_bug.cgi?id=765380 or
https://bugzilla.gnome.org/show_bug.cgi?id=765271 and possibly
addressed in 1.1.29; similar for CVE-2016-4612.
fixes would be:
https://git.gnome.org/browse/libxslt/commit/?id=5d0c6565bab5b9b7efceb33b626916d22b4101a7
https://git.gnome.org/browse/libxslt/commit/?id=d8862309f08054218b28e2c8f5fb3cb2f650cac7
given the above, these were fixed in the upstream 1.1.29 release
sbettie
incorporated patches into USN 3271-1

References