Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13118

Опубликовано: 30 июн. 2019
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

Отчет

  • This issue affects the version of libxslt as shipped with Red Hat Gluster Storage 3, as it includes the affected code which allows uninitialized read.
  • This issue affects the versions of libxslt as shipped with Red Hat Enterprise Linux 5, 6, 7 and 8. Red Hat Product Security has rated this issue as having a security impact of Low.
  • Red Hat OpenStack Platform versions 9, 10, 13, & 14 are marked WONTFIX as they will inherit fixes from the underlying RHEL layer. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxsltOut of support scope
Red Hat Enterprise Linux 6libxsltOut of support scope
Red Hat Enterprise Linux 7libxsltFix deferred
Red Hat Enterprise Linux 8libxsltFix deferred
Red Hat OpenStack Platform 10 (Newton)libxsltWill not fix
Red Hat OpenStack Platform 13 (Queens)libxsltWill not fix
Red Hat OpenStack Platform 14 (Rocky)libxsltWill not fix
Red Hat OpenStack Platform 9 (Mitaka)libxsltWill not fix
Red Hat Storage 3libxsltAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1728541libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character

EPSS

Процентиль: 77%
0.01027
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

CVSS3: 5.3
nvd
больше 6 лет назад

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

CVSS3: 5.3
debian
больше 6 лет назад

In numbers.c in libxslt 1.1.33, a type holding grouping characters of ...

CVSS3: 7.5
github
больше 3 лет назад

libxslt Type Confusion vulnerability that affects Nokogiri

CVSS3: 7.5
fstec
около 7 лет назад

Уязвимость функции xsltNumberFormatDecimal библиотеки libxslt, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 77%
0.01027
Низкий

5.3 Medium

CVSS3