{"id":"CVE-2019-13118","details":"In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.","aliases":["GHSA-cf46-6xxh-pc75"],"modified":"2026-04-16T04:36:02.167675254Z","published":"2019-07-01T02:15:09.800Z","related":["SUSE-SU-2019:1867-1","SUSE-SU-2020:1409-1","openSUSE-SU-2020:0731-1","openSUSE-SU-2024:11017-1"],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOYJKXPQCUNBMMQJWYXOR6QRUJZHEDRZ/"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/31"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Aug/21"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210346"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Aug/15"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/38"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Aug/22"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/35"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/42"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210358"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20200122-0003/"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210353"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/37"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210351"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210356"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Aug/13"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/23"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00020.html"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/40"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/41"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2019/11/17/2"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Aug/14"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/37"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Aug/23"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4164-1/"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/26"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20190806-0004/"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210348"},{"type":"ADVISORY","url":"https://support.apple.com/kb/HT210357"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Aug/25"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Jul/36"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Aug/11"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/22"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Jul/24"},{"type":"REPORT","url":"https://oss-fuzz.com/testcase-detail/5197371471822848"},{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15069"},{"type":"FIX","url":"https://gitlab.gnome.org/GNOME/libxslt/commit/6ce8de69330783977dd14f6569419489875fb71b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/GNOME/libxslt","events":[{"introduced":"0"},{"last_affected":"f1eb717f04d9cc297cc5e58e94b81ac96f47e741"},{"fixed":"6ce8de69330783977dd14f6569419489875fb71b"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"1.1.33"}]}}],"versions":["1.1.23","1.1.24","CVE-2015-7995","LIBXSLT_0_0_0","LIBXSLT_0_10_0","LIBXSLT_0_11_0","LIBXSLT_0_12_0","LIBXSLT_0_13_0","LIBXSLT_0_14_0","LIBXSLT_0_1_0","LIBXSLT_0_3_0","LIBXSLT_0_4_0","LIBXSLT_0_6_0","LIBXSLT_0_7_0","LIBXSLT_0_8_0","LIBXSLT_0_9_0","LIBXSLT_1_0_0","LIBXSLT_1_0_10","LIBXSLT_1_0_11","LIBXSLT_1_0_12","LIBXSLT_1_0_13","LIBXSLT_1_0_14","LIBXSLT_1_0_16","LIBXSLT_1_0_17","LIBXSLT_1_0_18","LIBXSLT_1_0_19","LIBXSLT_1_0_2","LIBXSLT_1_0_20","LIBXSLT_1_0_21","LIBXSLT_1_0_22","LIBXSLT_1_0_23","LIBXSLT_1_0_24","LIBXSLT_1_0_25","LIBXSLT_1_0_26","LIBXSLT_1_0_27","LIBXSLT_1_0_28","LIBXSLT_1_0_29","LIBXSLT_1_0_3","LIBXSLT_1_0_30","LIBXSLT_1_0_31","LIBXSLT_1_0_32","LIBXSLT_1_0_33","LIBXSLT_1_0_4","LIBXSLT_1_0_5","LIBXSLT_1_0_6","LIBXSLT_1_0_7","LIBXSLT_1_0_8","LIBXSLT_1_0_9","LIBXSLT_1_1_0","LIBXSLT_1_1_1","LIBXSLT_1_1_10","LIBXSLT_1_1_11","LIBXSLT_1_1_12","LIBXSLT_1_1_13","LIBXSLT_1_1_14","LIBXSLT_1_1_15","LIBXSLT_1_1_16","LIBXSLT_1_1_17","LIBXSLT_1_1_18","LIBXSLT_1_1_2","LIBXSLT_1_1_21","LIBXSLT_1_1_22","LIBXSLT_1_1_3","LIBXSLT_1_1_4","LIBXSLT_1_1_5","LIBXSLT_1_1_6","LIBXSLT_1_1_7","LIBXSLT_1_1_8","LIBXSLT_1_1_9","LIXSLT_0_5_0","v1.1.25","v1.1.26","v1.1.27","v1.1.27-rc1","v1.1.28","v1.1.29","v1.1.29-rc1","v1.1.29-rc2","v1.1.30","v1.1.30-rc1","v1.1.30-rc2","v1.1.31","v1.1.31-rc1","v1.1.31-rc2","v1.1.32","v1.1.32-rc1","v1.1.32-rc2","v1.1.33","v1.1.33-rc1","v1.1.33-rc2"],"database_specific":{"vanir_signatures_modified":"2026-04-11T08:55:53Z","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"15.1"}]},{"events":[{"introduced":"11.0"},{"last_affected":"11.50.2"}]},{"events":[{"introduced":"0"},{"last_affected":"1.8.0-update231"}]},{"events":[{"introduced":"0"},{"last_affected":"31"}]},{"events":[{"introduced":"0"},{"last_affected":"12.04"}]},{"events":[{"introduced":"0"},{"last_affected":"14.04"}]},{"events":[{"introduced":"0"},{"last_affected":"16.04"}]},{"events":[{"introduced":"0"},{"last_affected":"18.04"}]},{"events":[{"introduced":"0"},{"last_affected":"19.04"}]},{"events":[{"introduced":"0"},{"last_affected":"19.10"}]},{"events":[{"introduced":"0"},{"fixed":"7.13"}]},{"events":[{"introduced":"10.0"},{"fixed":"10.6"}]},{"events":[{"introduced":"0"},{"fixed":"12.9.6"}]},{"events":[{"introduced":"0"},{"fixed":"12.4"}]},{"events":[{"introduced":"0"},{"last_affected":"10.12.6-security_update_2019\\-001"}]},{"events":[{"introduced":"0"},{"last_affected":"10.12.6-security_update_2019\\-002"}]},{"events":[{"introduced":"0"},{"last_affected":"10.12.6-security_update_2019\\-003"}]},{"events":[{"introduced":"0"},{"last_affected":"10.13.6-security_update_2019\\-001"}]},{"events":[{"introduced":"0"},{"last_affected":"10.13.6-security_update_2019\\-002"}]},{"events":[{"introduced":"0"},{"last_affected":"10.13.6-security_update_2019\\-003"}]},{"events":[{"introduced":"10.4.6"},{"fixed":"10.14.6"}]},{"events":[{"introduced":"0"},{"fixed":"12.4"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13118.json","vanir_signatures":[{"signature_version":"v1","deprecated":false,"target":{"file":"libxslt/numbers.c"},"id":"CVE-2019-13118-3263aee1","signature_type":"Line","source":"https://gitlab.gnome.org/GNOME/libxslt@6ce8de69330783977dd14f6569419489875fb71b","digest":{"line_hashes":["63548434003007382491243147779269090701","116955402715987170288711090571509490340","132181306849488116102938414544554454906","93187498953954641064648803514721959766","132823863448370179372582377013990202357","265666783747685004834146135985363637479","171703248105306918475769584619162783632","288508257822198863614058207703000070769","302340413245318396511100747024947294852","165038232749100568916570064743469772324"],"threshold":0.9}},{"signature_version":"v1","deprecated":false,"id":"CVE-2019-13118-8bd3997b","target":{"file":"libxslt/numbers.c","function":"xsltFormatNumberConversion"},"signature_type":"Function","source":"https://gitlab.gnome.org/GNOME/libxslt@6ce8de69330783977dd14f6569419489875fb71b","digest":{"function_hash":"36987421056926122074875227490358574962","length":7644}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}