#VU18966 Information disclosure in libxslt - CVE-2019-13118
Published: July 2, 2019 / Updated: October 19, 2019
libxslt
Gnome Development Team
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to uninitialized stack data exposure in numbers.c in libxslt library when processing an invalid character/length combination in xsltNumberFormatDecimal. A remote attacker can gain pass specially crafted data to the application using the affected library and gain access to sensitive information.