CVE-2024-55549
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-55549 is a newly identified vulnerability affecting libxslt before version 1.1.43. The issue involves the xsltGetInheritedNsList function, which contains a use-after-free bug. Specifically, this vulnerability arises when result prefixes are improperly excluded during the function's execution. This can lead to memory being freed prematurely, and subsequent attempts to access that memory may result in unexpected behavior or crashes. Attackers can potentially exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition. System administrators are advised to update to the latest version of libxslt to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Xmlsoft Libxslt