CVE-2019-13118
01.07.2019, 02:15
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
Vendor | Product | Version |
---|---|---|
xmlsoft | libxslt | 1.1.33 |
opensuse | leap | 15.1 |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | cloud_backup | - |
netapp | clustered_data_ontap | - |
netapp | e-series_performance_analyzer | - |
netapp | e-series_santricity_management_plug-ins | - |
netapp | e-series_santricity_os_controller | 11.0 ≤ 𝑥 ≤ 11.50.2 |
netapp | e-series_santricity_storage_manager | - |
netapp | e-series_santricity_web_services | - |
netapp | oncommand_insight | - |
netapp | oncommand_workflow_automation | - |
netapp | ontap_select_deploy_administration_utility | - |
netapp | plug-in_for_symantec_netbackup | - |
netapp | santricity_unified_manager | - |
netapp | steelstore_cloud_integrated_storage | - |
oracle | jdk | 1.8.0 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 19.04 |
canonical | ubuntu_linux | 19.10 |
apple | icloud | 𝑥 < 7.13 |
apple | icloud | 10.0 ≤ 𝑥 < 10.6 |
apple | itunes | 𝑥 < 12.9.6 |
apple | iphone_os | 𝑥 < 12.4 |
apple | mac_os_x | 10.12.6:security_update_2019-001 |
apple | mac_os_x | 10.12.6:security_update_2019-002 |
apple | mac_os_x | 10.12.6:security_update_2019-003 |
apple | mac_os_x | 10.13.6:security_update_2019-001 |
apple | mac_os_x | 10.13.6:security_update_2019-002 |
apple | mac_os_x | 10.13.6:security_update_2019-003 |
apple | macos | 10.4.6 ≤ 𝑥 < 10.14.6 |
apple | tvos | 𝑥 < 12.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References