Back to search
CVE-2019-13118
Published: Jul 1, 2019
Modified: May 28, 2026
PUBLISHED
Description
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://oss-fuzz.com/testcase-detail/5197371471822848
x_refsource_MISC
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15069
x_refsource_MISC
https://support.apple.com/kb/HT210348
x_refsource_CONFIRM
https://support.apple.com/kb/HT210353
x_refsource_CONFIRM
https://support.apple.com/kb/HT210351
x_refsource_CONFIRM
[debian-lts-announce] 20190722 [SECURITY] [DLA 1860-1] libxslt security update
mailing-list
x_refsource_MLIST
https://support.apple.com/kb/HT210346
x_refsource_CONFIRM
20190723 APPLE-SA-2019-7-22-1 iOS 12.4
mailing-list
x_refsource_BUGTRAQ
20190723 APPLE-SA-2019-7-22-5 tvOS 12.4
mailing-list
x_refsource_BUGTRAQ
20190723 APPLE-SA-2019-7-22-4 watchOS 5.3
mailing-list
x_refsource_BUGTRAQ
20190723 APPLE-SA-2019-7-22-4 watchOS 5.3
mailing-list
x_refsource_FULLDISC
20190723 APPLE-SA-2019-7-22-1 iOS 12.4
mailing-list
x_refsource_FULLDISC
20190723 APPLE-SA-2019-7-22-2 macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
mailing-list
x_refsource_FULLDISC
20190723 APPLE-SA-2019-7-22-5 tvOS 12.4
mailing-list
x_refsource_FULLDISC
https://support.apple.com/kb/HT210356
x_refsource_CONFIRM
https://support.apple.com/kb/HT210357
x_refsource_CONFIRM
https://support.apple.com/kb/HT210358
x_refsource_CONFIRM
20190724 APPLE-SA-2019-7-23-2 iTunes for Windows 12.9.6
mailing-list
x_refsource_BUGTRAQ
20190724 APPLE-SA-2019-7-23-3 iCloud for Windows 10.6
mailing-list
x_refsource_BUGTRAQ
20190724 APPLE-SA-2019-7-23-1 iCloud for Windows 7.13
mailing-list
x_refsource_BUGTRAQ
20190726 APPLE-SA-2019-7-23-3 iCloud for Windows 10.6
mailing-list
x_refsource_FULLDISC
20190726 APPLE-SA-2019-7-23-1 iCloud for Windows 7.13
mailing-list
x_refsource_FULLDISC
20190726 APPLE-SA-2019-7-23-2 iTunes for Windows 12.9.6
mailing-list
x_refsource_FULLDISC
https://security.netapp.com/advisory/ntap-20190806-0004/
x_refsource_CONFIRM
20190814 APPLE-SA-2019-8-13-2 Additional information for APPLE-SA-2019-7-22-1 iOS 12.4
mailing-list
x_refsource_BUGTRAQ
20190814 APPLE-SA-2019-8-13-3 Additional information for APPLE-SA-2019-7-22-4 watchOS 5.3
mailing-list
x_refsource_BUGTRAQ
20190814 APPLE-SA-2019-8-13-4 Additional information for APPLE-SA-2019-7-22-5 tvOS 12.4
mailing-list
x_refsource_BUGTRAQ
20190816 APPLE-SA-2019-8-13-3 Additional information for APPLE-SA-2019-7-22-4 watchOS 5.3
mailing-list
x_refsource_FULLDISC
20190816 APPLE-SA-2019-8-13-2 Additional information for APPLE-SA-2019-7-22-1 iOS 12.4
mailing-list
x_refsource_FULLDISC
20190816 APPLE-SA-2019-8-13-4 Additional information for APPLE-SA-2019-7-22-5 tvOS 12.4
mailing-list
x_refsource_FULLDISC
USN-4164-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2019-fdf6ec39b4
vendor-advisory
x_refsource_FEDORA
[oss-security] 20191117 Nokogiri security update v1.10.5
mailing-list
x_refsource_MLIST
https://www.oracle.com/security-alerts/cpujan2020.html
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20200122-0003/
x_refsource_CONFIRM
openSUSE-SU-2020:0731
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now