CVE-2015-9019: Medium severity Xmlsoft Libxslt vulnerability
Published Apr 5, 2017
·Updated
In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.
Affected Software
1 affected component
Xmlsoft Libxslt<=1.1.29
Remediation
Patch Available
Patch Available
Event History
Apr 5, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9019?
CVE-2015-9019 is considered a medium severity vulnerability due to its potential to produce predictable outputs from the math.random function.
2
How do I fix CVE-2015-9019?
To fix CVE-2015-9019, update libxslt to version 1.1.30 or later where the issue is resolved.
3
Which versions of libxslt are affected by CVE-2015-9019?
CVE-2015-9019 affects libxslt version 1.1.29 and earlier.
4
What impact does CVE-2015-9019 have on applications using libxslt?
CVE-2015-9019 can lead to predictability in random number generation, which can affect cryptographic operations and overall security.
5
Is there a workaround for CVE-2015-9019 if I cannot update libxslt?
No specific workaround is recommended for CVE-2015-9019, and updating to a secure version is the best course of action.