5.1
CVSSv2

CVE-2019-18197

Published: 18/10/2019 Updated: 24/08/2020
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

It exists that Libxslt incorrectly handled certain documents. An attacker could possibly use this issue to access sensitive information. This issue not affected Ubuntu 19.10. (CVE-2019-13117, CVE-2019-13118)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xmlsoft libxslt 1.1.33

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

canonical ubuntu linux 19.10

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #942646 libxslt: CVE-2019-18197 Package: src:libxslt; Maintainer for src:libxslt is Debian XML/SGML Group <debian-xml-sgml-pkgs@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 19 Oct 2019 12:06:02 UTC Severity: important Tags: security, upstream Fou ...
Several security issues were fixed in Libxslt ...
Synopsis Important: chromium-browser security update Type/Severity Security Advisory: Important Topic An update for chromium-browser is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Synopsis Moderate: libxslt security update Type/Severity Security Advisory: Moderate Topic An update for libxslt is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Moderate: libxslt security update Type/Severity Security Advisory: Moderate Topic An update for libxslt is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Low: OpenShift Container Platform 4340 security and bug fix update Type/Severity Security Advisory: Low Topic An update is now available for Red Hat OpenShift Container Platform 43Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring S ...
Synopsis Moderate: OpenShift Container Platform 46 compliance-operator security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for compliance-content-container, ose-compliance-openscap-container, ose-compliance-operator-container, and ose-compliance-operator-metadata-container ...
Synopsis Moderate: OpenShift Container Platform 46 compliance-operator security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for compliance-content-container, ose-compliance-openscap-container, ose-compliance-operator-container, and ose-compliance-operator-metadata-container ...
Synopsis Moderate: Red Hat OpenShift Container Storage 460 security, bug fix, enhancement update Type/Severity Security Advisory: Moderate Topic Updated images are now available for Red Hat OpenShift Container Storage 460 on Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as ha ...
libxslt through 1133 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded (CVE-2019-11068) In xsltCopyText in transformc in libxslt 1133, a pointer vari ...
libxslt through 1133 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded (CVE-2019-11068) In xsltCopyText in transformc in libxslt 1133, a pointer vari ...
Severity Unknown Remote Unknown Type Unknown Description AVG-1092 chromium 7903945130-2 800398787-1 Unknown Fixed ...
The Chrome team is delighted to announce the promotion of Chrome 80 to the stable channel for Windows, Mac and Linux This will roll out over the coming days/weeks Chrome 800398787 contains a number of fixes and improvements -- a list of changes is available in the log Watch out for upcoming Chrome and Chromium blog po ...

Github Repositories

on GitLab CI

Practice of Handolint: DL3026 DL3003 SC2164 Normally, vulnerability scanner clair could be set to the threshold 'Medium' and in the current example there will be: cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2019-13627 cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2019-18197 This exposures are solved by updating the version of nginx, FROM quayio/jiteso