Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-13117

Опубликовано: 01 июл. 2019
Источник: debian

Описание

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxsltfixed1.1.32-2.1package
libxsltfixed1.1.32-2.1~deb10u1busterpackage
libxsltfixed1.1.29-2.1+deb9u1stretchpackage

Примечания

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14471

  • https://gitlab.gnome.org/GNOME/libxslt/commit/c5eb6cf3aba0af048596106ed839b4ae17ecbcb1

  • https://oss-fuzz.com/testcase-detail/5631739747106816

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS3: 5.3
redhat
больше 6 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS3: 5.3
nvd
больше 6 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

github
больше 3 лет назад

Uninitialized read in Nokogiri gem

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость функции xsltNumberFormatInsertNumbers библиотеки libxslt, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации