@buherator Did I read https://gitlab.gnome.org/GNOME/libxslt/-/issues/139 correctly that they disclosed this even though some affected browser vendor (cough cough) is still affected? Feeling bad for them.
@buherator @ifsecure I was thinking of https://gitlab.gnome.org/GNOME/libxslt/-/issues/139#note_2421963 in particular.
(I did see the presentation, I was there :))
@buherator @ifsecure The CVE ID was just assigned last week, which doesn't make it a useful search term.
@buherator @ifsecure I mean there are lots of empty phrases in the advisories, like
> Impact: Processing maliciously crafted web content may lead to memory corruption
> Description: The issue was addressed with improved memory handling.
that's like... 90% of all browser bugs?