Information disclosure in libxslt - CVE-2019-13117

 

Information disclosure in libxslt - CVE-2019-13117

Published: July 2, 2019 / Updated: October 19, 2019


Vulnerability identifier: #VU18965
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13117
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to information disclosure in numbers.c in libxslt library where an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. A remote attacker can gain knowledge whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.


Affected software

libxslt
libxslt (Ubuntu package)
libxslt (Alpine package)
libxslt
Secure Remote Services (SRS) Virtual Edition
EMC ECS
Oracle Java SE
Opensuse
Fedora
Wyse ThinLinux
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Data Protection Search

How to mitigate CVE-2019-13117

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

libxslt (Ubuntu package) - addressed in versions 1.1.28-2.1ubuntu0.3, 1.1.29-5ubuntu0.2, 1.1.32-2ubuntu0.2, 1.1.33-0ubuntu1.1
libxslt (Alpine package) - update to 1.1.33-r3
Secure Remote Services (SRS) Virtual Edition - update to 3.46.00.04
libxslt - update to 1.1.33-4.fc31
Wyse ThinLinux - update to 2.2.1.01
EMC ECS - update to 3.5.0.1
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Data Protection Search - update to 19.3.0

External References

Related Security Bulletins