CVE-2019-13118

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-13118
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13118.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-13118
Aliases
Downstream
Related
Published
2019-07-01T02:15:09Z
Modified
2025-10-14T16:43:05.918624Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

References

Affected packages

Git / gitlab.gnome.org/GNOME/libxslt

Affected ranges

Type
GIT
Repo
https://gitlab.gnome.org/GNOME/libxslt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.1.23
1.1.24

Other

CVE-2015-7995
LIBXSLT_0_0_0
LIBXSLT_0_10_0
LIBXSLT_0_11_0
LIBXSLT_0_12_0
LIBXSLT_0_13_0
LIBXSLT_0_14_0
LIBXSLT_0_1_0
LIBXSLT_0_3_0
LIBXSLT_0_4_0
LIBXSLT_0_6_0
LIBXSLT_0_7_0
LIBXSLT_0_8_0
LIBXSLT_0_9_0
LIBXSLT_1_0_0
LIBXSLT_1_0_10
LIBXSLT_1_0_11
LIBXSLT_1_0_12
LIBXSLT_1_0_13
LIBXSLT_1_0_14
LIBXSLT_1_0_16
LIBXSLT_1_0_17
LIBXSLT_1_0_18
LIBXSLT_1_0_19
LIBXSLT_1_0_2
LIBXSLT_1_0_20
LIBXSLT_1_0_21
LIBXSLT_1_0_22
LIBXSLT_1_0_23
LIBXSLT_1_0_24
LIBXSLT_1_0_25
LIBXSLT_1_0_26
LIBXSLT_1_0_27
LIBXSLT_1_0_28
LIBXSLT_1_0_29
LIBXSLT_1_0_3
LIBXSLT_1_0_30
LIBXSLT_1_0_31
LIBXSLT_1_0_32
LIBXSLT_1_0_33
LIBXSLT_1_0_4
LIBXSLT_1_0_5
LIBXSLT_1_0_6
LIBXSLT_1_0_7
LIBXSLT_1_0_8
LIBXSLT_1_0_9
LIBXSLT_1_1_0
LIBXSLT_1_1_1
LIBXSLT_1_1_10
LIBXSLT_1_1_11
LIBXSLT_1_1_12
LIBXSLT_1_1_13
LIBXSLT_1_1_14
LIBXSLT_1_1_15
LIBXSLT_1_1_16
LIBXSLT_1_1_17
LIBXSLT_1_1_18
LIBXSLT_1_1_2
LIBXSLT_1_1_21
LIBXSLT_1_1_22
LIBXSLT_1_1_3
LIBXSLT_1_1_4
LIBXSLT_1_1_5
LIBXSLT_1_1_6
LIBXSLT_1_1_7
LIBXSLT_1_1_8
LIBXSLT_1_1_9
LIXSLT_0_5_0

v1.*

v1.1.25
v1.1.26
v1.1.27
v1.1.27-rc1
v1.1.28
v1.1.29
v1.1.29-rc1
v1.1.29-rc2
v1.1.30
v1.1.30-rc1
v1.1.30-rc2
v1.1.31
v1.1.31-rc1
v1.1.31-rc2
v1.1.32
v1.1.32-rc1
v1.1.32-rc2
v1.1.33
v1.1.33-rc1
v1.1.33-rc2

Database specific

{
    "vanir_signatures": [
        {
            "id": "CVE-2019-13118-3263aee1",
            "signature_type": "Line",
            "target": {
                "file": "libxslt/numbers.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "63548434003007382491243147779269090701",
                    "116955402715987170288711090571509490340",
                    "132181306849488116102938414544554454906",
                    "93187498953954641064648803514721959766",
                    "132823863448370179372582377013990202357",
                    "265666783747685004834146135985363637479",
                    "171703248105306918475769584619162783632",
                    "288508257822198863614058207703000070769",
                    "302340413245318396511100747024947294852",
                    "165038232749100568916570064743469772324"
                ],
                "threshold": 0.9
            },
            "signature_version": "v1",
            "source": "https://gitlab.gnome.org/GNOME/libxslt@6ce8de69330783977dd14f6569419489875fb71b"
        },
        {
            "id": "CVE-2019-13118-8bd3997b",
            "signature_type": "Function",
            "target": {
                "file": "libxslt/numbers.c",
                "function": "xsltFormatNumberConversion"
            },
            "deprecated": false,
            "digest": {
                "length": 7644.0,
                "function_hash": "36987421056926122074875227490358574962"
            },
            "signature_version": "v1",
            "source": "https://gitlab.gnome.org/GNOME/libxslt@6ce8de69330783977dd14f6569419489875fb71b"
        }
    ]
}