Back to search
CVE-2019-18197
Published: Oct 18, 2019
Modified: May 28, 2026
PUBLISHED
Description
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15914
x_refsource_MISC
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15768
x_refsource_MISC
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15746
x_refsource_MISC
USN-4164-1
vendor-advisory
x_refsource_UBUNTU
[debian-lts-announce] 20191027 [SECURITY] [DLA 1973-1] libxslt security update
mailing-list
x_refsource_MLIST
https://security.netapp.com/advisory/ntap-20191031-0004/
x_refsource_CONFIRM
[oss-security] 20191117 Nokogiri security update v1.10.5
mailing-list
x_refsource_MLIST
openSUSE-SU-2020:0189
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:0210
vendor-advisory
x_refsource_SUSE
RHSA-2020:0514
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0233
vendor-advisory
x_refsource_SUSE
https://www.oracle.com/security-alerts/cpuapr2020.html
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20200416-0004/
x_refsource_CONFIRM
openSUSE-SU-2020:0731
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now