CVE-2025-24855 - CERT CVE
ID CVE-2025-24855
Sažetak numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
Reference
CVSS
Base: 7.8
Impact: 5.8
Exploitability:1.4
Pristup
VektorSloženostAutentikacija
LOCAL HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE HIGH HIGH
CVSS vektor CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Zadnje važnije ažuriranje 14-03-2025 - 02:15
Objavljeno 14-03-2025 - 02:15