Debian 10694 Published by

Debian GNU/Linux has received two security updates: A libxslt update for both Debian 12 and 13 and an openjdk-17 update for Debian 11 LTS

[DSA 5979-1] libxslt security update
[DLA 4275-1] openjdk-17 security update




[SECURITY] [DSA 5979-1] libxslt security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5979-1 security@debian.org
https://www.debian.org/security/ Aron Xu
August 19, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libxslt
CVE ID : CVE-2023-40403 CVE-2025-7424
Debian Bug : 1108074 1109123

Two vunlerabilities were found in libxslt, the XSLT 1.0 processing library,
which may lead to information disclosure and DoS attack.

CVE-2023-40403

Information disclosure with weak memory handling of generated-id()

CVE-2025-7424

Type confusion in xmlNode.psvi between stylesheet and source nodes,
which may allow an attacker to crash the application or corrupt memory.

For the oldstable distribution (bookworm), these problems have been fixed
in version 1.1.35-1+deb12u2.

For the stable distribution (trixie), these problems have been fixed in
version 1.1.35-1.2+deb13u1.

We recommend that you upgrade your libxslt packages.

For the detailed security status of libxslt please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libxslt

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4275-1] openjdk-17 security update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4275-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
August 19, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : openjdk-17
Version : 17.0.16+8-1~deb11u1
CVE ID : CVE-2025-30749 CVE-2025-30754 CVE-2025-50059 CVE-2025-50106

Several vulnerabilities have been discovered in the OpenJDK Java runtime,
which may result in denial of service, information disclosure or weakened
TLS connections.

For Debian 11 bullseye, these problems have been fixed in version
17.0.16+8-1~deb11u1.

We recommend that you upgrade your openjdk-17 packages.

For the detailed security status of openjdk-17 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/openjdk-17

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS