CVE-2019-13117

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

medium 5.3 CVSS 3.1
Published: Jul 1, 2019
Modified: May 28, 2026
Vendor: Xmlsoft
Product: Libxslt
Versions: 1.1.33,8.0,12.04,14.04,16.04,18.04,19.04,19.10,31,15.1

Description

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

References

Related CVEs