CVE-2019-13118

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Aug/11 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Aug/13 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Aug/14 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Aug/15 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jul/22 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jul/23 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jul/24 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jul/26 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jul/31 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jul/37 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2019/Jul/38 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2019/11/17/2 Mailing List Third Party Advisory
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15069 Permissions Required
https://gitlab.gnome.org/GNOME/libxslt/commit/6ce8de69330783977dd14f6569419489875fb71b Patch Third Party Advisory
https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E
https://lists.debian.org/debian-lts-announce/2019/07/msg00020.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOYJKXPQCUNBMMQJWYXOR6QRUJZHEDRZ/
https://oss-fuzz.com/testcase-detail/5197371471822848 Permissions Required
https://seclists.org/bugtraq/2019/Aug/21 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Aug/22 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Aug/23 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Aug/25 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jul/35 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jul/36 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jul/37 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jul/40 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jul/41 Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Jul/42 Mailing List Third Party Advisory
https://security.netapp.com/advisory/ntap-20190806-0004/ Third Party Advisory
https://security.netapp.com/advisory/ntap-20200122-0003/ Third Party Advisory
https://support.apple.com/kb/HT210346 Third Party Advisory
https://support.apple.com/kb/HT210348 Third Party Advisory
https://support.apple.com/kb/HT210351 Third Party Advisory
https://support.apple.com/kb/HT210353 Third Party Advisory
https://support.apple.com/kb/HT210356 Third Party Advisory
https://support.apple.com/kb/HT210357 Third Party Advisory
https://support.apple.com/kb/HT210358 Third Party Advisory
https://usn.ubuntu.com/4164-1/ Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:xmlsoft:libxslt:1.1.33:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:e-series_santricity_management_plug-ins:-:*:*:*:*:vmware_vcenter:*:*
cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:e-series_santricity_storage_manager:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:e-series_santricity_web_services:-:*:*:*:*:web_services_proxy:*:*
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:plug-in_for_symantec_netbackup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:santricity_unified_manager:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:oracle:jdk:1.8.0:update231:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

Configuration 6 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*

Configuration 7 (hide)

OR cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*
cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*
cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.12.6:security_update_2019-001:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.12.6:security_update_2019-002:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.12.6:security_update_2019-003:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2019-001:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2019-002:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.13.6:security_update_2019-003:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:03

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E', 'name': '[bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'MLIST'}
  • {'url': 'https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E', 'name': '[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'MLIST'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IOYJKXPQCUNBMMQJWYXOR6QRUJZHEDRZ/', 'name': 'FEDORA-2019-fdf6ec39b4', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOYJKXPQCUNBMMQJWYXOR6QRUJZHEDRZ/ -
  • () https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E -
  • () https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E -

Information

Published : 2019-07-01 02:15

Updated : 2024-02-28 17:08


NVD link : CVE-2019-13118

Mitre link : CVE-2019-13118

CVE.ORG link : CVE-2019-13118


JSON object : View

Products Affected

netapp

  • active_iq_unified_manager
  • e-series_santricity_management_plug-ins
  • santricity_unified_manager
  • e-series_santricity_storage_manager
  • plug-in_for_symantec_netbackup
  • clustered_data_ontap
  • e-series_santricity_web_services
  • steelstore_cloud_integrated_storage
  • e-series_santricity_os_controller
  • oncommand_insight
  • ontap_select_deploy_administration_utility
  • e-series_performance_analyzer
  • cloud_backup
  • oncommand_workflow_automation

apple

  • iphone_os
  • itunes
  • tvos
  • icloud
  • mac_os_x
  • macos

xmlsoft

  • libxslt

fedoraproject

  • fedora

opensuse

  • leap

oracle

  • jdk

canonical

  • ubuntu_linux
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')