CVE-2019-13117
moderate-risk
Published 2019-07-01
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
Do I need to act?
~
4.5% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.3/10
Medium
NETWORK
/ LOW complexity
Affected Products (11)
References (26)
Issue Tracking
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14471
Permissions Required
https://oss-fuzz.com/testcase-detail/5631739747106816
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190806-0004/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200122-0003/
Third Party Advisory
https://usn.ubuntu.com/4164-1/
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html
Issue Tracking
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14471
and 6 more references
45
/ 100
moderate-risk
Severity
21/34 · High
Exploitability
8/34 · Low
Exposure
16/34 · Moderate