In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
2019-07-01T02:15:09.800
2024-11-21T04:24:13.817
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | xmlsoft | libxslt | 1.1.33 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | clustered_data_ontap | - | Yes |
Application | netapp | e-series_performance_analyzer | - | Yes |
Application | netapp | e-series_santricity_management_plug-ins | - | Yes |
Application | netapp | e-series_santricity_os_controller | ≤ 11.50.2 | Yes |
Application | netapp | e-series_santricity_storage_manager | - | Yes |
Application | netapp | e-series_santricity_web_services | - | Yes |
Application | netapp | oncommand_insight | - | Yes |
Application | netapp | oncommand_workflow_automation | - | Yes |
Application | netapp | ontap_select_deploy_administration_utility | - | Yes |
Application | netapp | plug-in_for_symantec_netbackup | - | Yes |
Application | netapp | santricity_unified_manager | - | Yes |
Application | netapp | steelstore_cloud_integrated_storage | - | Yes |
Application | oracle | jdk | 1.8.0 | Yes |
Operating System | fedoraproject | fedora | 31 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 19.04 | Yes |
Operating System | canonical | ubuntu_linux | 19.10 | Yes |
Application | apple | icloud | < 7.13 | Yes |
Application | apple | icloud | < 10.6 | Yes |
Application | apple | itunes | < 12.9.6 | Yes |
Operating System | apple | iphone_os | < 12.4 | Yes |
Operating System | apple | mac_os_x | 10.12.6 | Yes |
Operating System | apple | mac_os_x | 10.12.6 | Yes |
Operating System | apple | mac_os_x | 10.12.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | mac_os_x | 10.13.6 | Yes |
Operating System | apple | macos | < 10.14.6 | Yes |
Operating System | apple | tvos | < 12.4 | Yes |