CVE-2019-13117: Canonical Ubuntu Linux
Medium severity, CVSS 5.3. EPSS: 6.5% chance of exploitation in the next 30 days.
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 31 only
- Opensuse Leap: version 15.1 only
- Oracle Openjdk: version 8 only
- Xmlsoft Libxslt: version 1.1.33 only
Published 2019-07-01. Last modified 2026-06-17.