CVE-2019-13117

Related Vulnerabilities: CVE-2019-13117  

Impact: Low Public Date: 2019-06-30 CWE: CWE-134 Bugzilla: 1728546: CVE-2019-13117 libxslt: an xsl number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

The MITRE CVE dictionary describes this issue as:

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

Find out more about CVE-2019-13117 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 3.3
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact None
Availability Impact None

Affected Packages State

Platform Package State
Red Hat OpenStack Platform 9.0 libxslt Under investigation
Red Hat OpenStack Platform 14.0 (Rocky) libxslt Under investigation
Red Hat OpenStack Platform 13.0 (Queens) libxslt Under investigation
Red Hat OpenStack Platform 10 libxslt Under investigation
Red Hat Gluster Storage 3 libxslt Under investigation
Red Hat Enterprise Linux 8 libxslt Under investigation
Red Hat Enterprise Linux 7 libxslt Under investigation
Red Hat Enterprise Linux 6 libxslt Under investigation
Red Hat Enterprise Linux 5 libxslt Under investigation