CVE-2019-13118: Apple iCloud
Medium severity, CVSS 5.3. EPSS: 5.2% chance of exploitation in the next 30 days.
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
Affected products
- Apple iCloud: before 7.13 (fixed in 7.13); from 10.0, before 10.6 (fixed in 10.6)
- Apple iPhone OS: before 12.4 (fixed in 12.4)
- Apple iTunes: before 12.9.6 (fixed in 12.9.6)
- Apple Mac OS X: version 10.12.6 only; version 10.13.6 only
- Apple macOS: from 10.4.6, before 10.14.6 (fixed in 10.14.6)
- Apple tvOS: before 12.4 (fixed in 12.4)
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
- Fedoraproject Fedora: version 31 only
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Cloud Backup: affected versions not specified
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp E-Series Performance Analyzer: affected versions not specified
- Netapp E-Series Santricity Management Plug-Ins: affected versions not specified
- Netapp E-Series Santricity OS Controller: from 11.0, up to and including 11.50.2
- Netapp E-Series Santricity Storage Manager: affected versions not specified
- Netapp E-Series Santricity Web Services: affected versions not specified
- Netapp Oncommand Insight: affected versions not specified
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Netapp Plug-In For Symantec Netbackup: affected versions not specified
- Netapp Santricity Unified Manager: affected versions not specified
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Opensuse Leap: version 15.1 only
- Oracle JDK: version 1.8.0 only
- Xmlsoft Libxslt: version 1.1.33 only
Published 2019-07-01. Last modified 2026-06-17.