ISOMAN

CVE

CVE-2019-13117

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

Severity
MEDIUM
CVSS
5.3
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html
  2. http://www.openwall.com/lists/oss-security/2019/11/17/2
  3. https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14471
  4. https://gitlab.gnome.org/GNOME/libxslt/commit/c5eb6cf3aba0af048596106ed839b4ae17ecbcb1
  5. https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
  6. https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
  7. https://lists.debian.org/debian-lts-announce/2019/07/msg00020.html
  8. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOYJKXPQCUNBMMQJWYXOR6QRUJZHEDRZ/
  9. https://oss-fuzz.com/testcase-detail/5631739747106816
  10. https://security.netapp.com/advisory/ntap-20190806-0004/
  11. https://security.netapp.com/advisory/ntap-20200122-0003/
  12. https://usn.ubuntu.com/4164-1/
  13. https://www.oracle.com/security-alerts/cpujan2020.html
  14. http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html
  15. http://www.openwall.com/lists/oss-security/2019/11/17/2
  16. https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14471
  17. https://gitlab.gnome.org/GNOME/libxslt/commit/c5eb6cf3aba0af048596106ed839b4ae17ecbcb1
  18. https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
  19. https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
  20. https://lists.debian.org/debian-lts-announce/2019/07/msg00020.html