Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-13118

Опубликовано: 01 июл. 2019
Источник: debian
EPSS Низкий

Описание

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxsltfixed1.1.32-2.1package
libxsltfixed1.1.32-2.1~deb10u1busterpackage
libxsltfixed1.1.29-2.1+deb9u1stretchpackage

Примечания

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15069

  • https://gitlab.gnome.org/GNOME/libxslt/commit/6ce8de69330783977dd14f6569419489875fb71b

  • https://oss-fuzz.com/testcase-detail/5197371471822848

EPSS

Процентиль: 77%
0.01027
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

CVSS3: 5.3
redhat
больше 6 лет назад

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

CVSS3: 5.3
nvd
больше 6 лет назад

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

CVSS3: 7.5
github
больше 3 лет назад

libxslt Type Confusion vulnerability that affects Nokogiri

CVSS3: 7.5
fstec
около 7 лет назад

Уязвимость функции xsltNumberFormatDecimal библиотеки libxslt, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 77%
0.01027
Низкий