Source: libxslt Version: 1.1.32-2 Severity: important Tags: security upstream
Hi, The following vulnerability was published for libxslt. CVE-2019-13117[0]: | In numbers.c in libxslt 1.1.33, an xsl:number with certain format | strings could lead to a uninitialized read in | xsltNumberFormatInsertNumbers. This could allow an attacker to discern | whether a byte on the stack contains the characters A, a, I, i, or 0, | or any other character. The oss-fuzz report and testcases are not public at this moment, but still filling the bug according to source code view and patch to be applied. I have no futher details unfortunately. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2019-13117 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13117 [1] https://gitlab.gnome.org/GNOME/libxslt/commit/c5eb6cf3aba0af048596106ed839b4ae17ecbcb1 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

