Information disclosure in libxslt - CVE-2019-13118

 

Information disclosure in libxslt - CVE-2019-13118

Published: July 2, 2019 / Updated: October 19, 2019


Vulnerability identifier: #VU18966
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13118
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to uninitialized stack data exposure in numbers.c in libxslt library when processing an invalid character/length combination in xsltNumberFormatDecimal. A remote attacker can gain pass specially crafted data to the application using the affected library and gain access to sensitive information.


Affected software

libxslt
libxslt (Ubuntu package)
libxslt (Alpine package)
libxslt
Secure Remote Services (SRS) Virtual Edition
EMC ECS
Oracle Java SE
Opensuse
Fedora
Wyse ThinLinux
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Data Protection Search

How to mitigate CVE-2019-13118

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

libxslt (Ubuntu package) - addressed in versions 1.1.28-2.1ubuntu0.3, 1.1.29-5ubuntu0.2, 1.1.32-2ubuntu0.2, 1.1.33-0ubuntu1.1
libxslt (Alpine package) - update to 1.1.33-r3
Secure Remote Services (SRS) Virtual Edition - update to 3.46.00.04
libxslt - update to 1.1.33-4.fc31
Wyse ThinLinux - update to 2.2.1.01
EMC ECS - update to 3.5.0.1
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Data Protection Search - update to 19.3.0

External References

Related Security Bulletins