Skip to content

Commit 2c7db7b

Browse files
[AUTO-CHERRYPICK] Upgrade libxslt to fix CVE-2024-55549 and CVE-2025-24855 [High] - branch 3.0-dev (#13243)
Co-authored-by: sindhu-karri <[email protected]>
1 parent 64aa7ec commit 2c7db7b

File tree

7 files changed

+17
-15
lines changed

7 files changed

+17
-15
lines changed

SPECS/libxslt/libxslt.signatures.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
22
"Signatures": {
3-
"libxslt-1.1.39.tar.xz": "2a20ad621148339b0759c4d4e96719362dee64c9a096dbba625ba053846349f0"
3+
"libxslt-1.1.43.tar.xz": "5a3d6b383ca5afc235b171118e90f5ff6aa27e9fea3303065231a6d403f0183a"
44
}
55
}

SPECS/libxslt/libxslt.spec

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
%define majminorver %(echo %{version} | cut -d. -f 1,2)
22
Summary: Libxslt is the XSLT C library developed for the GNOME project. XSLT is a an XML language to define transformation for XML.
33
Name: libxslt
4-
Version: 1.1.39
4+
Version: 1.1.43
55
Release: 1%{?dist}
66
License: MIT
77
Vendor: Microsoft Corporation
@@ -55,10 +55,10 @@ make %{?_smp_mflags} check
5555

5656
%files
5757
%defattr(-,root,root)
58-
%license COPYING
58+
%license Copyright
59+
%doc AUTHORS NEWS README.md FEATURES
5960
%{_libdir}/*.so.*
6061
%{_libdir}/*.sh
61-
%{_libdir}/libxslt-plugins
6262
%{_bindir}/*
6363
%{_mandir}/man1/*
6464

@@ -71,12 +71,14 @@ make %{?_smp_mflags} check
7171
%{_includedir}/*
7272
%{_docdir}/*
7373
%{_datadir}/gtk-doc/*
74-
%{_datadir}/aclocal/*
7574
%{_mandir}/man3/*
7675

7776

7877

7978
%changelog
79+
* Tue Mar 18 2025 Sindhu Karri <[email protected]> - 1.1.43-1
80+
- Upgrade to version 1.1.43 to fix CVE-2024-55549 and CVE-2025-24855
81+
8082
* Tue Nov 28 2023 Andrew Phelps <[email protected]> - 1.1.39-1
8183
- Upgrade to version 1.1.39
8284

cgmanifest.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12061,8 +12061,8 @@
1206112061
"type": "other",
1206212062
"other": {
1206312063
"name": "libxslt",
12064-
"version": "1.1.39",
12065-
"downloadUrl": "https://download.gnome.org/sources/libxslt/1.1/libxslt-1.1.39.tar.xz"
12064+
"version": "1.1.43",
12065+
"downloadUrl": "https://download.gnome.org/sources/libxslt/1.1/libxslt-1.1.43.tar.xz"
1206612066
}
1206712067
}
1206812068
},

toolkit/resources/manifests/package/pkggen_core_aarch64.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -225,7 +225,7 @@ libgpg-error-1.47-1.azl3.aarch64.rpm
225225
libgcrypt-1.10.2-1.azl3.aarch64.rpm
226226
libksba-1.6.4-1.azl3.aarch64.rpm
227227
libksba-devel-1.6.4-1.azl3.aarch64.rpm
228-
libxslt-1.1.39-1.azl3.aarch64.rpm
228+
libxslt-1.1.43-1.azl3.aarch64.rpm
229229
npth-1.6-4.azl3.aarch64.rpm
230230
pinentry-1.2.1-1.azl3.aarch64.rpm
231231
gnupg2-2.4.4-2.azl3.aarch64.rpm

toolkit/resources/manifests/package/pkggen_core_x86_64.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -225,7 +225,7 @@ libgpg-error-1.47-1.azl3.x86_64.rpm
225225
libgcrypt-1.10.2-1.azl3.x86_64.rpm
226226
libksba-1.6.4-1.azl3.x86_64.rpm
227227
libksba-devel-1.6.4-1.azl3.x86_64.rpm
228-
libxslt-1.1.39-1.azl3.x86_64.rpm
228+
libxslt-1.1.43-1.azl3.x86_64.rpm
229229
npth-1.6-4.azl3.x86_64.rpm
230230
pinentry-1.2.1-1.azl3.x86_64.rpm
231231
gnupg2-2.4.4-2.azl3.x86_64.rpm

toolkit/resources/manifests/package/toolchain_aarch64.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -245,9 +245,9 @@ libxcrypt-devel-4.4.36-2.azl3.aarch64.rpm
245245
libxml2-2.11.5-4.azl3.aarch64.rpm
246246
libxml2-debuginfo-2.11.5-4.azl3.aarch64.rpm
247247
libxml2-devel-2.11.5-4.azl3.aarch64.rpm
248-
libxslt-1.1.39-1.azl3.aarch64.rpm
249-
libxslt-debuginfo-1.1.39-1.azl3.aarch64.rpm
250-
libxslt-devel-1.1.39-1.azl3.aarch64.rpm
248+
libxslt-1.1.43-1.azl3.aarch64.rpm
249+
libxslt-debuginfo-1.1.43-1.azl3.aarch64.rpm
250+
libxslt-devel-1.1.43-1.azl3.aarch64.rpm
251251
lua-5.4.6-1.azl3.aarch64.rpm
252252
lua-debuginfo-5.4.6-1.azl3.aarch64.rpm
253253
lua-devel-5.4.6-1.azl3.aarch64.rpm

toolkit/resources/manifests/package/toolchain_x86_64.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -253,9 +253,9 @@ libxml2-devel-2.11.5-4.azl3.x86_64.rpm
253253
libxcrypt-4.4.36-2.azl3.x86_64.rpm
254254
libxcrypt-debuginfo-4.4.36-2.azl3.x86_64.rpm
255255
libxcrypt-devel-4.4.36-2.azl3.x86_64.rpm
256-
libxslt-1.1.39-1.azl3.x86_64.rpm
257-
libxslt-debuginfo-1.1.39-1.azl3.x86_64.rpm
258-
libxslt-devel-1.1.39-1.azl3.x86_64.rpm
256+
libxslt-1.1.43-1.azl3.x86_64.rpm
257+
libxslt-debuginfo-1.1.43-1.azl3.x86_64.rpm
258+
libxslt-devel-1.1.43-1.azl3.x86_64.rpm
259259
lua-5.4.6-1.azl3.x86_64.rpm
260260
lua-debuginfo-5.4.6-1.azl3.x86_64.rpm
261261
lua-devel-5.4.6-1.azl3.x86_64.rpm

0 commit comments

Comments
 (0)