Information disclosure in libxslt - CVE-2019-13117
Published: July 2, 2019 / Updated: October 19, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to information disclosure in numbers.c in libxslt library where an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. A remote attacker can gain knowledge whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
Affected software
libxslt (Ubuntu package)
libxslt (Alpine package)
libxslt
Secure Remote Services (SRS) Virtual Edition
EMC ECS
Oracle Java SE
Opensuse
Fedora
Wyse ThinLinux
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Data Protection Search
How to mitigate CVE-2019-13117
libxslt (Alpine package) - update to 1.1.33-r3
Secure Remote Services (SRS) Virtual Edition - update to 3.46.00.04
libxslt - update to 1.1.33-4.fc31
Wyse ThinLinux - update to 2.2.1.01
EMC ECS - update to 3.5.0.1
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Data Protection Search - update to 19.3.0
External References
Related Security Bulletins
- Multiple vulnerabilities in libxslt
- Ubuntu update for Libxslt
- OpenSUSE Linux update for libxslt
- Multiple vulnerabilities in Java SE
- Information disclosure in libxslt (Alpine package)
- Multiple vulnerabilities in Dell EMC ECS
- Multiple vulnerabilities in Dell EMC Secure Remote Services (SRS) Virtual Edition
- Multiple vulnerabilities in Dell EMC Data Protection Search
- Multiple vulnerabilities in Dell Wyse ThinLinux
- Fedora 31 update for libxslt
- Dell EMC Unity update for third-party components