Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13117

Опубликовано: 30 июн. 2019
Источник: redhat
CVSS3: 5.3

Описание

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

Отчет

RH ProdSec scores this vulnerability as "Low" due to complex prerequisites for successful exploitation.

  • The attacker must be able to supply an XSLT file to a system that automatically processes it using libxslt.
  • An xsl:number element must be present with a malformed format string designed to cause an uninitialized read in xsltNumberFormatInsertNumbers.
  • While a successful exploitation will force libxslt to process memory content as if it were a format string, the attacker cannot directly control memory contents but can observe differences in output to infer values.
  • This issue affects the version of libxslt as shipped with Red Hat Gluster Storage 3, as it includes the affected code which allows uninitialized read.
  • Red Hat OpenStack Platform versions 9, 10, 13, & 14 are marked WONTFIX as they will inherit fixes from the underlying RHEL layer.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxsltOut of support scope
Red Hat Enterprise Linux 6libxsltOut of support scope
Red Hat Enterprise Linux 7libxsltFix deferred
Red Hat Enterprise Linux 8libxsltFix deferred
Red Hat OpenStack Platform 10 (Newton)libxsltWill not fix
Red Hat OpenStack Platform 13 (Queens)libxsltWill not fix
Red Hat OpenStack Platform 14 (Rocky)libxsltWill not fix
Red Hat OpenStack Platform 9 (Mitaka)libxsltWill not fix
Red Hat Storage 3libxsltAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-134
https://bugzilla.redhat.com/show_bug.cgi?id=1728546libxslt: an xsl number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS3: 5.3
nvd
больше 6 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS3: 5.3
debian
больше 6 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format stri ...

github
больше 3 лет назад

Uninitialized read in Nokogiri gem

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость функции xsltNumberFormatInsertNumbers библиотеки libxslt, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

5.3 Medium

CVSS3