Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-18197

Опубликовано: 18 окт. 2019
Источник: debian
EPSS Низкий

Описание

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxsltfixed1.1.32-2.2package
libxsltfixed1.1.32-2.2~deb10u1busterpackage
libxsltfixed1.1.29-2.1+deb9u2stretchpackage

Примечания

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15746

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15768

  • https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15914

  • https://gitlab.gnome.org/GNOME/libxslt/commit/2232473733b7313d67de8836ea3b29eec6e8e285

EPSS

Процентиль: 81%
0.0154
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

CVSS3: 7.5
redhat
почти 6 лет назад

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

CVSS3: 7.5
nvd
почти 6 лет назад

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

suse-cvrf
почти 5 лет назад

Security update for libxslt

suse-cvrf
больше 5 лет назад

Security update for libxslt

EPSS

Процентиль: 81%
0.0154
Низкий