CVE-2019-13117: Medium severity Xmlsoft Libxslt vulnerability
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-13117.
What is the severity level of CVE-2019-13117?
The severity level of CVE-2019-13117 is medium with a CVSS score of 5.3.
How does CVE-2019-13117 affect the affected software?
CVE-2019-13117 affects libxslt 1.1.33 as well as certain versions of Debian Linux, Ubuntu Linux, Fedora, OpenSUSE, and Oracle OpenJDK.
What is the potential impact of CVE-2019-13117?
CVE-2019-13117 could allow an attacker to discern the contents of a byte on the stack, potentially compromising the confidentiality of sensitive information.
Where can I find more information about CVE-2019-13117?
You can find more information about CVE-2019-13117 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html](http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html), [http://www.openwall.com/lists/oss-security/2019/11/17/2](http://www.openwall.com/lists/oss-security/2019/11/17/2), [https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14471](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14471).