Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-18197

Опубликовано: 18 окт. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.1
CVSS3: 7.5

Описание

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

РелизСтатусПримечание
bionic

released

1.1.29-5ubuntu0.2
devel

DNE

disco

released

1.1.32-2ubuntu0.2
eoan

released

1.1.33-0ubuntu1.1
esm-infra-legacy/trusty

not-affected

1.1.28-2ubuntu0.2+esm1
esm-infra/bionic

not-affected

1.1.29-5ubuntu0.2
esm-infra/xenial

not-affected

1.1.28-2.1ubuntu0.3
precise/esm

not-affected

1.1.26-8ubuntu1.6
trusty

ignored

end of standard support
trusty/esm

released

1.1.28-2ubuntu0.2+esm1

Показывать по

EPSS

Процентиль: 81%
0.0154
Низкий

5.1 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 6 лет назад

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

CVSS3: 7.5
nvd
почти 6 лет назад

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

CVSS3: 7.5
debian
почти 6 лет назад

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable i ...

suse-cvrf
почти 5 лет назад

Security update for libxslt

suse-cvrf
больше 5 лет назад

Security update for libxslt

EPSS

Процентиль: 81%
0.0154
Низкий

5.1 Medium

CVSS2

7.5 High

CVSS3