{"id":"CVE-2019-13118","details":"In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.","aliases":["GHSA-cf46-6xxh-pc75"],"modified":"2026-01-30T12:33:51.574775Z","published":"2019-07-01T02:15:09.800Z","related":["MGASA-2019-0313","SUSE-SU-2019:1867-1","SUSE-SU-2020:1409-1","openSUSE-SU-2020:0731-1","openSUSE-SU-2024:11017-1"],"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOYJKXPQCUNBMMQJWYXOR6QRUJZHEDRZ/"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Aug/11"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Aug/13"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Aug/14"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Aug/15"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/22"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/23"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/24"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/26"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/31"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/37"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/38"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2019/11/17/2"},{"type":"ADVISORY","url":"https://gitlab.gnome.org/GNOME/libxslt/commit/6ce8de69330783977dd14f6569419489875fb71b"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00020.html"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Aug/21"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Aug/22"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Aug/23"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Aug/25"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/35"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/36"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/37"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/40"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/41"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/42"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20190806-0004/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20200122-0003/"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210346"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210348"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210351"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210353"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210356"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210357"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210358"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4164-1/"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15069"},{"type":"REPORT","url":"https://oss-fuzz.com/testcase-detail/5197371471822848"},{"type":"FIX","url":"https://gitlab.gnome.org/GNOME/libxslt/commit/6ce8de69330783977dd14f6569419489875fb71b"},{"type":"ARTICLE","url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Aug/11"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Aug/13"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Aug/14"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Aug/15"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Jul/22"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Jul/23"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Jul/24"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Jul/26"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Jul/31"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Jul/37"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2019/Jul/38"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2019/11/17/2"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00020.html"},{"type":"ARTICLE","url":"https://seclists.org/bugtraq/2019/Aug/21"},{"type":"ARTICLE","url":"https://seclists.org/bugtraq/2019/Aug/22"},{"type":"ARTICLE","url":"https://seclists.org/bugtraq/2019/Aug/23"},{"type":"ARTICLE","url":"https://seclists.org/bugtraq/2019/Aug/25"},{"type":"ARTICLE","url":"https://seclists.org/bugtraq/2019/Jul/35"},{"type":"ARTICLE","url":"https://seclists.org/bugtraq/2019/Jul/36"},{"type":"ARTICLE","url":"https://seclists.org/bugtraq/2019/Jul/37"},{"type":"ARTICLE","url":"https://seclists.org/bugtraq/2019/Jul/40"},{"type":"ARTICLE","url":"https://seclists.org/bugtraq/2019/Jul/41"},{"type":"ARTICLE","url":"https://seclists.org/bugtraq/2019/Jul/42"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/GNOME/libxslt","events":[{"introduced":"0"},{"fixed":"6ce8de69330783977dd14f6569419489875fb71b"}]}],"versions":["1.1.23","1.1.24","CVE-2015-7995","LIBXSLT_0_0_0","LIBXSLT_0_10_0","LIBXSLT_0_11_0","LIBXSLT_0_12_0","LIBXSLT_0_13_0","LIBXSLT_0_14_0","LIBXSLT_0_1_0","LIBXSLT_0_3_0","LIBXSLT_0_4_0","LIBXSLT_0_6_0","LIBXSLT_0_7_0","LIBXSLT_0_8_0","LIBXSLT_0_9_0","LIBXSLT_1_0_0","LIBXSLT_1_0_10","LIBXSLT_1_0_11","LIBXSLT_1_0_12","LIBXSLT_1_0_13","LIBXSLT_1_0_14","LIBXSLT_1_0_16","LIBXSLT_1_0_17","LIBXSLT_1_0_18","LIBXSLT_1_0_19","LIBXSLT_1_0_2","LIBXSLT_1_0_20","LIBXSLT_1_0_21","LIBXSLT_1_0_22","LIBXSLT_1_0_23","LIBXSLT_1_0_24","LIBXSLT_1_0_25","LIBXSLT_1_0_26","LIBXSLT_1_0_27","LIBXSLT_1_0_28","LIBXSLT_1_0_29","LIBXSLT_1_0_3","LIBXSLT_1_0_30","LIBXSLT_1_0_31","LIBXSLT_1_0_32","LIBXSLT_1_0_33","LIBXSLT_1_0_4","LIBXSLT_1_0_5","LIBXSLT_1_0_6","LIBXSLT_1_0_7","LIBXSLT_1_0_8","LIBXSLT_1_0_9","LIBXSLT_1_1_0","LIBXSLT_1_1_1","LIBXSLT_1_1_10","LIBXSLT_1_1_11","LIBXSLT_1_1_12","LIBXSLT_1_1_13","LIBXSLT_1_1_14","LIBXSLT_1_1_15","LIBXSLT_1_1_16","LIBXSLT_1_1_17","LIBXSLT_1_1_18","LIBXSLT_1_1_2","LIBXSLT_1_1_21","LIBXSLT_1_1_22","LIBXSLT_1_1_3","LIBXSLT_1_1_4","LIBXSLT_1_1_5","LIBXSLT_1_1_6","LIBXSLT_1_1_7","LIBXSLT_1_1_8","LIBXSLT_1_1_9","LIXSLT_0_5_0","v1.1.25","v1.1.26","v1.1.27","v1.1.27-rc1","v1.1.28","v1.1.29","v1.1.29-rc1","v1.1.29-rc2","v1.1.30","v1.1.30-rc1","v1.1.30-rc2","v1.1.31","v1.1.31-rc1","v1.1.31-rc2","v1.1.32","v1.1.32-rc1","v1.1.32-rc2","v1.1.33","v1.1.33-rc1","v1.1.33-rc2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13118.json","vanir_signatures":[{"id":"CVE-2019-13118-3263aee1","signature_type":"Line","deprecated":false,"target":{"file":"libxslt/numbers.c"},"digest":{"threshold":0.9,"line_hashes":["63548434003007382491243147779269090701","116955402715987170288711090571509490340","132181306849488116102938414544554454906","93187498953954641064648803514721959766","132823863448370179372582377013990202357","265666783747685004834146135985363637479","171703248105306918475769584619162783632","288508257822198863614058207703000070769","302340413245318396511100747024947294852","165038232749100568916570064743469772324"]},"source":"https://gitlab.gnome.org/GNOME/libxslt@6ce8de69330783977dd14f6569419489875fb71b","signature_version":"v1"},{"id":"CVE-2019-13118-8bd3997b","signature_type":"Function","deprecated":false,"target":{"function":"xsltFormatNumberConversion","file":"libxslt/numbers.c"},"digest":{"length":7644,"function_hash":"36987421056926122074875227490358574962"},"source":"https://gitlab.gnome.org/GNOME/libxslt@6ce8de69330783977dd14f6569419489875fb71b","signature_version":"v1"}]}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}