CVE-2024-55549

Public on 2025-03-14
Modified on 2025-03-19
Description

xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.

Severity
Important
See what this means
CVSS v3 Base Score
7.8
See breakdown

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 1 libxslt 2025-04-17 ALAS-2025-1968
Amazon Linux 2 - Core libxslt 2025-04-16 ALAS2-2025-2823
Amazon Linux 2023 libxslt 2025-04-01 ALAS2023-2025-909

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
NVD CVSSv3 7.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H