type: security subject: Updated libxslt packages fix security vulnerability CVE: - CVE-2019-11068 src: 6: core: - libxslt-1.1.29-6.1.mga6 description: | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded (CVE-2019-11068). references: - https://bugs.mageia.org/show_bug.cgi?id=24705 - https://usn.ubuntu.com/usn/usn-3947-1 ID: MGASA-2019-0175