CVE-2019-13118
published 2019-07-01CVE-2019-13118: In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
5.15%
91.5th percentile
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.13 | 7.13 |
| apple | icloud | >= 10.0 < 10.6 | 10.6 |
| apple | icloud_for_windows | — | — |
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 12.4 | 12.4 |
| apple | itunes | < 12.9.6 | 12.9.6 |
| apple | itunes_12.9.6_for_windows | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | macos | >= 10.4.6 < 10.14.6 | 10.14.6 |
| apple | macos_mojave_10.14.6_security_update_2019-004_high_sierra_security_update_2019-0 | — | — |
| apple | tvos | < 12.4 | 12.4 |
| apple | tvos | — | — |
| apple | watchos | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libxslt | < libxslt 1.1.32-2.1 (bookworm) | libxslt 1.1.32-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| netapp | e-series_santricity_os_controller | 11.0 – 11.50.2 | — |
| nokogiri | nokogiri | >= 0 < 1.10.5 | 1.10.5 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_oracle7.5MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
libxslt Type Confusion vulnerability that affects Nokogiri
ghsa·2022-05-24
CVE-2019-13118 [HIGH] CWE-843 libxslt Type Confusion vulnerability that affects Nokogiri
libxslt Type Confusion vulnerability that affects Nokogiri
In `numbers.c` in libxslt 1.1.33, a type holding grouping characters of an `xsl:number` instruction was too narrow and an invalid character/length combination could be passed to `xsltNumberFormatDecimal`, leading to a read of uninitialized stack data.
Nokogiri prior to version 1.10.5 used a vulnerable version of libxslt. Nokogiri 1.10.5 updated libxslt to version 1.1.34 to address this and other vulnerabilities in libxslt.
OSV
libxslt Type Confusion vulnerability that affects Nokogiri
osv·2022-05-24
CVE-2019-13118 [HIGH] libxslt Type Confusion vulnerability that affects Nokogiri
libxslt Type Confusion vulnerability that affects Nokogiri
In `numbers.c` in libxslt 1.1.33, a type holding grouping characters of an `xsl:number` instruction was too narrow and an invalid character/length combination could be passed to `xsltNumberFormatDecimal`, leading to a read of uninitialized stack data.
Nokogiri prior to version 1.10.5 used a vulnerable version of libxslt. Nokogiri 1.10.5 updated libxslt to version 1.1.34 to address this and other vulnerabilities in libxslt.
OSV
libxslt vulnerabilities
osv·2019-10-22·CVSS 5.3
CVE-2019-13117 [MEDIUM] libxslt vulnerabilities
libxslt vulnerabilities
It was discovered that Libxslt incorrectly handled certain documents.
An attacker could possibly use this issue to access sensitive information.
This issue not affected Ubuntu 19.10. (CVE-2019-13117, CVE-2019-13118)
It was discovered that Libxslt incorrectly handled certain documents.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-18197)
OSV
CVE-2019-13118: In numbers
osv·2019-07-01·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118: In numbers
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
Oracle
Oracle Oracle Java SE Risk Matrix: JavaFX (libxslt) — CVE-2019-13118
vendor_oracle·2020-01-15·CVSS 7.5
CVE-2019-13118 [MEDIUM] Oracle Oracle Java SE Risk Matrix: JavaFX (libxslt) — CVE-2019-13118
Oracle Oracle Java SE Risk Matrix: JavaFX (libxslt) vulnerability
CVE: CVE-2019-13118
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Ubuntu
Libxslt vulnerabilities
vendor_ubuntu·2019-10-22·CVSS 5.3
CVE-2019-13117 [MEDIUM] Libxslt vulnerabilities
Title: Libxslt vulnerabilities
Summary: Several security issues were fixed in Libxslt.
It was discovered that Libxslt incorrectly handled certain documents.
An attacker could possibly use this issue to access sensitive information.
This issue not affected Ubuntu 19.10. (CVE-2019-13117, CVE-2019-13118)
It was discovered that Libxslt incorrectly handled certain documents.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-18197)
Instructions: In general, a standard system update will make all the necessary changes.
make all the necessary changes.
Apple
CVE-2019-13118: iCloud for Windows 10.6
vendor_apple·2019-07-23·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118: iCloud for Windows 10.6
Apple Security Update: About the security content of iCloud for Windows 10.6
Product: iCloud for Windows
Version: 10.6
CVE: CVE-2019-13118
Component: About Apple security updates
Impact: A remote attacker may be able to view sensitive information
Description: A stack overflow was addressed with improved input validation.
Apple
CVE-2019-13118: iTunes 12.9.6 for Windows
vendor_apple·2019-07-23·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118: iTunes 12.9.6 for Windows
Apple Security Update: About the security content of iTunes 12.9.6 for Windows
Product: iTunes 12.9.6 for Windows
CVE: CVE-2019-13118
Component: About Apple security updates
Impact: A remote attacker may be able to view sensitive information
Description: A stack overflow was addressed with improved input validation.
Apple
CVE-2019-13118: iCloud for Windows 7.13
vendor_apple·2019-07-23·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118: iCloud for Windows 7.13
Apple Security Update: About the security content of iCloud for Windows 7.13
Product: iCloud for Windows
Version: 7.13
CVE: CVE-2019-13118
Component: About Apple security updates
Impact: A remote attacker may be able to view sensitive information
Description: A stack overflow was addressed with improved input validation.
Apple
CVE-2019-13118: iOS 12.4
vendor_apple·2019-07-22·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118: iOS 12.4
Apple Security Update: About the security content of iOS 12.4
Product: iOS
Version: 12.4
CVE: CVE-2019-13118
Component: Image Processing
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: A denial of service issue was addressed with improved validation.
Apple
CVE-2019-13118: tvOS 12.4
vendor_apple·2019-07-22·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118: tvOS 12.4
Apple Security Update: About the security content of tvOS 12.4
Product: tvOS
Version: 12.4
CVE: CVE-2019-13118
Component: Image Processing
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: A denial of service issue was addressed with improved validation.
Apple
CVE-2019-13118: macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
vendor_apple·2019-07-22·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118: macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
Apple Security Update: About the security content of macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
Product: macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra
CVE: CVE-2019-13118
Component: IOAcceleratorFamily
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2019-13118: watchOS 5.3
vendor_apple·2019-07-22·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118: watchOS 5.3
Apple Security Update: About the security content of watchOS 5.3
Product: watchOS
Version: 5.3
CVE: CVE-2019-13118
Component: Kernel
Impact: An application may be able to read restricted memory
Description: A validation issue was addressed with improved input sanitization.
Red Hat
libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character
vendor_redhat·2019-06-30·CVSS 5.3
CVE-2019-13118 [MEDIUM] CWE-119 libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character
libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
A vulnerability was found in libxslt within the numbers.c file, where a type holding grouping characters of an xsl:number instruction was too narrow, this flaw allowed an invalid character/length combination to be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data. This could result in undefined behavior or potential information disclosure.
Statement: * This issue affects the version of libxslt as shipped with
Debian
CVE-2019-13118: libxslt - In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:num...
vendor_debian·2019·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118: libxslt - In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:num...
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
Scope: local
bookworm: resolved (fixed in 1.1.32-2.1)
bullseye: resolved (fixed in 1.1.32-2.1)
forky: resolved (fixed in 1.1.32-2.1)
sid: resolved (fixed in 1.1.32-2.1)
trixie: resolved (fixed in 1.1.32-2.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13118 mingw-libxslt: libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character [fedora-all]
bugzilla·2019-07-10·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118 mingw-libxslt: libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character [fedora-all]
CVE-2019-13118 mingw-libxslt: libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fed
Bugzilla
CVE-2019-13118 mingw-libxslt: libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character [epel-7]
bugzilla·2019-07-10·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118 mingw-libxslt: libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character [epel-7]
CVE-2019-13118 mingw-libxslt: libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg comm
Bugzilla
CVE-2019-13118 libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character
bugzilla·2019-07-10·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118 libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character
CVE-2019-13118 libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character
A vulnerability was discovered in numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
Upstream commit:
https://gitlab.gnome.org/GNOME/libxslt/commit/6ce8de69330783977dd14f6569419489875fb71b
Discussion:
Created libxslt tracking bugs for this issue:
Affects: fedora-all [bug 1728542]
Created mingw-libxslt tracking bugs for this issue:
Affects: epel-7 [bug 1728544]
Affects: fedora-all [bug 1728543]
---
There's a bug on libxslt at function xsltFormatNumberConversion() where an
Bugzilla
CVE-2019-13118 libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character [fedora-all]
bugzilla·2019-07-10·CVSS 5.3
CVE-2019-13118 [MEDIUM] CVE-2019-13118 libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character [fedora-all]
CVE-2019-13118 libxslt: read of uninitialized stack data due to too narrow xsl:number instruction and an invalid character [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mess
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.htmlhttp://seclists.org/fulldisclosure/2019/Aug/11http://seclists.org/fulldisclosure/2019/Aug/13http://seclists.org/fulldisclosure/2019/Aug/14http://seclists.org/fulldisclosure/2019/Aug/15http://seclists.org/fulldisclosure/2019/Jul/22http://seclists.org/fulldisclosure/2019/Jul/23http://seclists.org/fulldisclosure/2019/Jul/24http://seclists.org/fulldisclosure/2019/Jul/26http://seclists.org/fulldisclosure/2019/Jul/31http://seclists.org/fulldisclosure/2019/Jul/37http://seclists.org/fulldisclosure/2019/Jul/38http://www.openwall.com/lists/oss-security/2019/11/17/2https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15069https://gitlab.gnome.org/GNOME/libxslt/commit/6ce8de69330783977dd14f6569419489875fb71bhttps://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/07/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOYJKXPQCUNBMMQJWYXOR6QRUJZHEDRZ/https://oss-fuzz.com/testcase-detail/5197371471822848https://seclists.org/bugtraq/2019/Aug/21https://seclists.org/bugtraq/2019/Aug/22https://seclists.org/bugtraq/2019/Aug/23https://seclists.org/bugtraq/2019/Aug/25https://seclists.org/bugtraq/2019/Jul/35https://seclists.org/bugtraq/2019/Jul/36https://seclists.org/bugtraq/2019/Jul/37https://seclists.org/bugtraq/2019/Jul/40https://seclists.org/bugtraq/2019/Jul/41https://seclists.org/bugtraq/2019/Jul/42https://security.netapp.com/advisory/ntap-20190806-0004/https://security.netapp.com/advisory/ntap-20200122-0003/https://support.apple.com/kb/HT210346https://support.apple.com/kb/HT210348https://support.apple.com/kb/HT210351https://support.apple.com/kb/HT210353https://support.apple.com/kb/HT210356https://support.apple.com/kb/HT210357https://support.apple.com/kb/HT210358https://usn.ubuntu.com/4164-1/https://www.oracle.com/security-alerts/cpujan2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.htmlhttp://seclists.org/fulldisclosure/2019/Aug/11http://seclists.org/fulldisclosure/2019/Aug/13http://seclists.org/fulldisclosure/2019/Aug/14http://seclists.org/fulldisclosure/2019/Aug/15http://seclists.org/fulldisclosure/2019/Jul/22http://seclists.org/fulldisclosure/2019/Jul/23http://seclists.org/fulldisclosure/2019/Jul/24http://seclists.org/fulldisclosure/2019/Jul/26http://seclists.org/fulldisclosure/2019/Jul/31http://seclists.org/fulldisclosure/2019/Jul/37http://seclists.org/fulldisclosure/2019/Jul/38http://www.openwall.com/lists/oss-security/2019/11/17/2https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15069https://gitlab.gnome.org/GNOME/libxslt/commit/6ce8de69330783977dd14f6569419489875fb71bhttps://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/07/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOYJKXPQCUNBMMQJWYXOR6QRUJZHEDRZ/https://oss-fuzz.com/testcase-detail/5197371471822848https://seclists.org/bugtraq/2019/Aug/21https://seclists.org/bugtraq/2019/Aug/22https://seclists.org/bugtraq/2019/Aug/23https://seclists.org/bugtraq/2019/Aug/25https://seclists.org/bugtraq/2019/Jul/35https://seclists.org/bugtraq/2019/Jul/36https://seclists.org/bugtraq/2019/Jul/37https://seclists.org/bugtraq/2019/Jul/40https://seclists.org/bugtraq/2019/Jul/41https://seclists.org/bugtraq/2019/Jul/42https://security.netapp.com/advisory/ntap-20190806-0004/https://security.netapp.com/advisory/ntap-20200122-0003/https://support.apple.com/kb/HT210346https://support.apple.com/kb/HT210348https://support.apple.com/kb/HT210351https://support.apple.com/kb/HT210353https://support.apple.com/kb/HT210356https://support.apple.com/kb/HT210357https://support.apple.com/kb/HT210358https://usn.ubuntu.com/4164-1/https://www.oracle.com/security-alerts/cpujan2020.html
2019-07-01
Published