From ${URL} : A heap overread vulnerability was found in xsltFormatNumberConversion function in libxslt. An empty decimal-separator could cause a heap overread. This can be exploited to leak a couple of bytes after the buffer that holds the pattern string. Upstream patch: https://git.gnome.org/browse/libxslt/commit/?id=eb1030de31165b68487f288308f9d1810fed6880 @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Not yet released, https://github.com/GNOME/libxslt/commit/eb1030de31165b68487f288308f9d1810fed6880
This patch made it to 1.1.30 release that I just added to the tree.
Added to existing GLSA.
This issue was resolved and addressed in GLSA 201804-01 at https://security.gentoo.org/glsa/201804-01 by GLSA coordinator Aaron Bauman (b-man).