{"id":"ECHO-6324-537e-5d75","summary":"According to the upstream, math.random() is not intended to meet cryptographic\nrandomness requirements. Proper seeding should be handled by the application\nusing libxslt. Additionally, calling srand() from a library is considered bad practice,\nas applications may expect deterministic behavior from random(). \nhttps://security-tracker.debian.org/tracker/CVE-2015-9019\n","modified":"2026-09-15T03:42:50.838122609Z","published":"2025-09-15T01:08:50.891390Z","withdrawn":"2025-08-03T16:59:07.284Z","upstream":["CVE-2015-9019","GHSA-8xxg-m548-vx69"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2015-9019"}],"affected":[{"package":{"name":"libxslt","ecosystem":"Echo","purl":"pkg:deb/echo/libxslt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.35-1+deb12u1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-6324-537e-5d75.json"}}],"schema_version":"1.9.0"}