Back to search
CVE-2019-13117
Published: Jul 1, 2019
Modified: May 28, 2026
PUBLISHED
Description
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://oss-fuzz.com/testcase-detail/5631739747106816
x_refsource_MISC
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14471
x_refsource_MISC
[debian-lts-announce] 20190722 [SECURITY] [DLA 1860-1] libxslt security update
mailing-list
x_refsource_MLIST
https://security.netapp.com/advisory/ntap-20190806-0004/
x_refsource_CONFIRM
USN-4164-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2019-fdf6ec39b4
vendor-advisory
x_refsource_FEDORA
[oss-security] 20191117 Nokogiri security update v1.10.5
mailing-list
x_refsource_MLIST
https://www.oracle.com/security-alerts/cpujan2020.html
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20200122-0003/
x_refsource_CONFIRM
openSUSE-SU-2020:0731
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now