Information disclosure in libxslt - CVE-2019-13118
Published: July 2, 2019 / Updated: October 19, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to uninitialized stack data exposure in numbers.c in libxslt library when processing an invalid character/length combination in xsltNumberFormatDecimal. A remote attacker can gain pass specially crafted data to the application using the affected library and gain access to sensitive information.
Affected software
libxslt (Ubuntu package)
libxslt (Alpine package)
libxslt
Secure Remote Services (SRS) Virtual Edition
EMC ECS
Oracle Java SE
Opensuse
Fedora
Wyse ThinLinux
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Data Protection Search
How to mitigate CVE-2019-13118
libxslt (Alpine package) - update to 1.1.33-r3
Secure Remote Services (SRS) Virtual Edition - update to 3.46.00.04
libxslt - update to 1.1.33-4.fc31
Wyse ThinLinux - update to 2.2.1.01
EMC ECS - update to 3.5.0.1
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Data Protection Search - update to 19.3.0
External References
Related Security Bulletins
- Multiple vulnerabilities in libxslt
- Ubuntu update for Libxslt
- OpenSUSE Linux update for libxslt
- Multiple vulnerabilities in Java SE
- Information disclosure in libxslt (Alpine package)
- Multiple vulnerabilities in Dell EMC ECS
- Multiple vulnerabilities in Dell EMC Secure Remote Services (SRS) Virtual Edition
- Multiple vulnerabilities in Dell EMC Data Protection Search
- Multiple vulnerabilities in Dell Wyse ThinLinux
- Fedora 31 update for libxslt
- Dell EMC Unity update for third-party components