Severity
7.5HIGH
EPSS
4.5%
top 10.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 18
Latest updateMay 24

Description

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages4 packages

Debianlibxslt< 1.1.32-2.2+3
Ubuntulibxslt< 1.1.28-2.1ubuntu0.3+2
NVDxmlsoft/libxslt1.1.33
RubyGemsnokogiri< 1.10.5

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 16.04, 18.04, 19.04, 19.10

Patches

🔴Vulnerability Details

5
GHSA
Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability2022-05-24
OSV
Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability2022-05-24
OSV
libxslt vulnerabilities2019-10-22
CVEList
CVE-2019-18197: In xsltCopyText in transform2019-10-18
OSV
CVE-2019-18197: In xsltCopyText in transform2019-10-18

📋Vendor Advisories

5
Oracle
Oracle Oracle Java SE Risk Matrix: JavaFX (libxslt) — CVE-2019-181972020-04-15
Chrome
Stable Channel Update for Desktop: CVE-2019-181972020-02-04
Ubuntu
Libxslt vulnerabilities2019-10-22
Red Hat
libxslt: use after free in xsltCopyText in transform.c could lead to information disclosure2019-10-18
Debian
CVE-2019-18197: libxslt - In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset...2019

💬Community

6
Bugzilla
CVE-2019-18197 mingw-libxslt: libxslt: use after free in xsltCopyText in transform.c leads to password disclosure [fedora-all]2019-11-11
Bugzilla
CVE-2019-18197 mingw-libxslt: libxslt: use after free in xsltCopyText in transform.c could lead to information disclosure [epel-7]2019-11-11
Bugzilla
CVE-2019-18197 libxslt: use after free in xsltCopyText in transform.c leads to password disclosure [fedora-all]2019-11-11
Bugzilla
CVE-2019-18197 libxslt: use after free in xsltCopyText in transform.c could lead to information disclosure2019-11-11
Bugzilla
CVE-2019-18197 mingw-libxslt: libxslt: use after free in xsltCopyText in transform.c could lead to information disclosure [fedora-all]2019-11-11
CVE-2019-18197 (HIGH CVSS 7.5) | In xsltCopyText in transform.c in l | cvebase.io