cbcvebase.
CVE-2019-13118
published 2019-07-01

CVE-2019-13118: In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
appleicloud< 7.137.13
appleicloud>= 10.0 < 10.610.6
appleicloud_for_windows
appleicloud_for_windows
appleios
appleiphone_os< 12.412.4
appleitunes< 12.9.612.9.6
appleitunes_12.9.6_for_windows
applemac_os_x
applemac_os_x
applemacos>= 10.4.6 < 10.14.610.14.6
applemacos_mojave_10.14.6_security_update_2019-004_high_sierra_security_update_2019-0
appletvos< 12.412.4
appletvos
applewatchos
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlibxslt< libxslt 1.1.32-2.1 (bookworm)libxslt 1.1.32-2.1 (bookworm)
fedoraprojectfedora
netappe-series_santricity_os_controller11.0 – 11.50.2
nokogirinokogiri>= 0 < 1.10.51.10.5

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM