CVE-2019-13117

Modified
Published: 01 Jul 2019, 01:27
Last modified:28 May 2026, 18:31

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
4.38% LOW
4% probability -0.08%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Jul 2019, 01:27
Published
Vulnerability first disclosed
28 May 2026, 18:31
Last Modified
Vulnerability information updated

Description

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 4.38% Percentile: 89%

Techniques & Countermeasures

  • CWE-908Use of Uninitialized Resource

    The product uses or accesses a resource that has not been initialized.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 16.04 | 18.04 | 19.04 | 19.10

  • debiandebian_linux

    8.0

  • fedoraprojectfedora

    31

  • opensuseleap

    15.1

  • oracleopenjdk

    8:update231

  • xmlsoftlibxslt

    1.1.33

References (13)