Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hm9-844j-jmxp

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью

Описание

Uninitialized read in Nokogiri gem

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

Пакеты

Наименование

nokogiri

rubygems
Затронутые версииВерсия исправления

< 1.10.5

1.10.5

EPSS

Процентиль: 89%
0.04457
Низкий

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS3: 5.3
redhat
больше 6 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS3: 5.3
nvd
больше 6 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS3: 5.3
debian
больше 6 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format stri ...

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость функции xsltNumberFormatInsertNumbers библиотеки libxslt, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 89%
0.04457
Низкий

Дефекты

CWE-908