CVE-2019-13117
—CVSS 3.1
5.3 medium
EPSS
6%p93
Published
()
Modified
Description
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
In the news0 stories
No ingested article mentions this CVE yet.