UBUNTU-CVE-2023-40403

Source
https://ubuntu.com/security/CVE-2023-40403
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-40403.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2023-40403
Related
Published
2023-09-27T15:19:00Z
Modified
2025-06-27T17:05:54Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information.

References

Affected packages

Ubuntu:Pro:14.04:LTS / libxslt

Package

Name
libxslt
Purl
pkg:deb/ubuntu/libxslt@1.1.28-2ubuntu0.2+esm3?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.28-2ubuntu0.2+esm3

Affected versions

1.*

1.1.28-2
1.1.28-2build1
1.1.28-2ubuntu0.1
1.1.28-2ubuntu0.2
1.1.28-2ubuntu0.2+esm1
1.1.28-2ubuntu0.2+esm2

Ecosystem specific

{
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.1.28-2ubuntu0.2+esm3",
            "binary_name": "libxslt1-dbg"
        },
        {
            "binary_version": "1.1.28-2ubuntu0.2+esm3",
            "binary_name": "libxslt1-dev"
        },
        {
            "binary_version": "1.1.28-2ubuntu0.2+esm3",
            "binary_name": "libxslt1-dev-dbgsym"
        },
        {
            "binary_version": "1.1.28-2ubuntu0.2+esm3",
            "binary_name": "libxslt1.1"
        },
        {
            "binary_version": "1.1.28-2ubuntu0.2+esm3",
            "binary_name": "libxslt1.1-dbgsym"
        },
        {
            "binary_version": "1.1.28-2ubuntu0.2+esm3",
            "binary_name": "python-libxslt1"
        },
        {
            "binary_version": "1.1.28-2ubuntu0.2+esm3",
            "binary_name": "python-libxslt1-dbg"
        },
        {
            "binary_version": "1.1.28-2ubuntu0.2+esm3",
            "binary_name": "python-libxslt1-dbgsym"
        },
        {
            "binary_version": "1.1.28-2ubuntu0.2+esm3",
            "binary_name": "xsltproc"
        },
        {
            "binary_version": "1.1.28-2ubuntu0.2+esm3",
            "binary_name": "xsltproc-dbgsym"
        }
    ],
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"
}

Ubuntu:Pro:16.04:LTS / libxslt

Package

Name
libxslt
Purl
pkg:deb/ubuntu/libxslt@1.1.28-2.1ubuntu0.3+esm2?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.28-2.1ubuntu0.3+esm2

Affected versions

1.*

1.1.28-2build2
1.1.28-2.1
1.1.28-2.1ubuntu0.1
1.1.28-2.1ubuntu0.2
1.1.28-2.1ubuntu0.3
1.1.28-2.1ubuntu0.3+esm1

Ecosystem specific

{
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.1.28-2.1ubuntu0.3+esm2",
            "binary_name": "libxslt1-dbg"
        },
        {
            "binary_version": "1.1.28-2.1ubuntu0.3+esm2",
            "binary_name": "libxslt1-dev"
        },
        {
            "binary_version": "1.1.28-2.1ubuntu0.3+esm2",
            "binary_name": "libxslt1-dev-dbgsym"
        },
        {
            "binary_version": "1.1.28-2.1ubuntu0.3+esm2",
            "binary_name": "libxslt1.1"
        },
        {
            "binary_version": "1.1.28-2.1ubuntu0.3+esm2",
            "binary_name": "libxslt1.1-dbgsym"
        },
        {
            "binary_version": "1.1.28-2.1ubuntu0.3+esm2",
            "binary_name": "python-libxslt1"
        },
        {
            "binary_version": "1.1.28-2.1ubuntu0.3+esm2",
            "binary_name": "python-libxslt1-dbg"
        },
        {
            "binary_version": "1.1.28-2.1ubuntu0.3+esm2",
            "binary_name": "xsltproc"
        },
        {
            "binary_version": "1.1.28-2.1ubuntu0.3+esm2",
            "binary_name": "xsltproc-dbgsym"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Ubuntu:Pro:18.04:LTS / libxslt

Package

Name
libxslt
Purl
pkg:deb/ubuntu/libxslt@1.1.29-5ubuntu0.3+esm1?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.29-5ubuntu0.3+esm1

Affected versions

1.*

1.1.29-2.1ubuntu1
1.1.29-4
1.1.29-5
1.1.29-5ubuntu0.1
1.1.29-5ubuntu0.2
1.1.29-5ubuntu0.3

Ecosystem specific

{
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.1.29-5ubuntu0.3+esm1",
            "binary_name": "libxslt1-dbg"
        },
        {
            "binary_version": "1.1.29-5ubuntu0.3+esm1",
            "binary_name": "libxslt1-dev"
        },
        {
            "binary_version": "1.1.29-5ubuntu0.3+esm1",
            "binary_name": "libxslt1.1"
        },
        {
            "binary_version": "1.1.29-5ubuntu0.3+esm1",
            "binary_name": "python-libxslt1"
        },
        {
            "binary_version": "1.1.29-5ubuntu0.3+esm1",
            "binary_name": "python-libxslt1-dbg"
        },
        {
            "binary_version": "1.1.29-5ubuntu0.3+esm1",
            "binary_name": "xsltproc"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Ubuntu:Pro:20.04:LTS / libxslt

Package

Name
libxslt
Purl
pkg:deb/ubuntu/libxslt@1.1.34-4ubuntu0.20.04.3+esm1?arch=source&distro=esm-infra/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.34-4ubuntu0.20.04.3+esm1

Affected versions

1.*

1.1.33-0ubuntu1
1.1.33-0ubuntu2
1.1.33-0ubuntu3
1.1.34-1
1.1.34-1ubuntu1
1.1.34-3
1.1.34-4
1.1.34-4ubuntu0.20.04.1
1.1.34-4ubuntu0.20.04.2
1.1.34-4ubuntu0.20.04.3

Ecosystem specific

{
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.1.34-4ubuntu0.20.04.3+esm1",
            "binary_name": "libxslt1-dev"
        },
        {
            "binary_version": "1.1.34-4ubuntu0.20.04.3+esm1",
            "binary_name": "libxslt1.1"
        },
        {
            "binary_version": "1.1.34-4ubuntu0.20.04.3+esm1",
            "binary_name": "libxslt1.1-dbgsym"
        },
        {
            "binary_version": "1.1.34-4ubuntu0.20.04.3+esm1",
            "binary_name": "xsltproc"
        },
        {
            "binary_version": "1.1.34-4ubuntu0.20.04.3+esm1",
            "binary_name": "xsltproc-dbgsym"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Ubuntu:22.04:LTS / libxslt

Package

Name
libxslt
Purl
pkg:deb/ubuntu/libxslt@1.1.34-4ubuntu0.22.04.4?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.34-4ubuntu0.22.04.4

Affected versions

1.*

1.1.34-4
1.1.34-4build1
1.1.34-4build2
1.1.34-4ubuntu0.22.04.1
1.1.34-4ubuntu0.22.04.2
1.1.34-4ubuntu0.22.04.3

Ecosystem specific

{
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.1.34-4ubuntu0.22.04.4",
            "binary_name": "libxslt1-dev"
        },
        {
            "binary_version": "1.1.34-4ubuntu0.22.04.4",
            "binary_name": "libxslt1.1"
        },
        {
            "binary_version": "1.1.34-4ubuntu0.22.04.4",
            "binary_name": "libxslt1.1-dbgsym"
        },
        {
            "binary_version": "1.1.34-4ubuntu0.22.04.4",
            "binary_name": "xsltproc"
        },
        {
            "binary_version": "1.1.34-4ubuntu0.22.04.4",
            "binary_name": "xsltproc-dbgsym"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:24.10 / libxslt

Package

Name
libxslt
Purl
pkg:deb/ubuntu/libxslt@1.1.39-0exp1ubuntu1.2?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.39-0exp1ubuntu1.2

Affected versions

1.*

1.1.39-0exp1build1
1.1.39-0exp1ubuntu1
1.1.39-0exp1ubuntu1.1

Ecosystem specific

{
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.1.39-0exp1ubuntu1.2",
            "binary_name": "libxslt1-dev"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu1.2",
            "binary_name": "libxslt1.1"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu1.2",
            "binary_name": "libxslt1.1-dbgsym"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu1.2",
            "binary_name": "xsltproc"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu1.2",
            "binary_name": "xsltproc-dbgsym"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:24.04:LTS / libxslt

Package

Name
libxslt
Purl
pkg:deb/ubuntu/libxslt@1.1.39-0exp1ubuntu0.24.04.2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.39-0exp1ubuntu0.24.04.2

Affected versions

1.*

1.1.35-1
1.1.39-0exp1
1.1.39-0exp1build1
1.1.39-0exp1ubuntu0.24.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.1.39-0exp1ubuntu0.24.04.2",
            "binary_name": "libxslt1-dev"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu0.24.04.2",
            "binary_name": "libxslt1.1"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu0.24.04.2",
            "binary_name": "libxslt1.1-dbgsym"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu0.24.04.2",
            "binary_name": "xsltproc"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu0.24.04.2",
            "binary_name": "xsltproc-dbgsym"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:25.04 / libxslt

Package

Name
libxslt
Purl
pkg:deb/ubuntu/libxslt@1.1.39-0exp1ubuntu4?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.39-0exp1ubuntu4

Affected versions

1.*

1.1.39-0exp1ubuntu1
1.1.39-0exp1ubuntu2
1.1.39-0exp1ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.1.39-0exp1ubuntu4",
            "binary_name": "libxslt1-dev"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu4",
            "binary_name": "libxslt1.1"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu4",
            "binary_name": "libxslt1.1-dbgsym"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu4",
            "binary_name": "xsltproc"
        },
        {
            "binary_version": "1.1.39-0exp1ubuntu4",
            "binary_name": "xsltproc-dbgsym"
        }
    ],
    "availability": "No subscription required"
}