CVE-2019-13118
CVE-2019-13118
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.htmlhttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15069http://seclists.org/fulldisclosure/2019/Aug/11http://seclists.org/fulldisclosure/2019/Aug/13http://seclists.org/fulldisclosure/2019/Aug/14http://seclists.org/fulldisclosure/2019/Aug/15http://seclists.org/fulldisclosure/2019/Jul/22http://seclists.org/fulldisclosure/2019/Jul/23http://seclists.org/fulldisclosure/2019/Jul/24http://seclists.org/fulldisclosure/2019/Jul/26http://seclists.org/fulldisclosure/2019/Jul/31http://seclists.org/fulldisclosure/2019/Jul/37