libxslt: use after free in xsltCopyText in transform.c could lead to information disclosure
Published Oct 18, 2019
7.5
HIGHCVSS 3.1
EPSS 4.36%
Description
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.
Affected products
No data.
Configuration 1
Running on/with
- n/a
Configuration 2
- 12.04
- 14.04
- 16.04
- 18.04
- 19.04
- 19.10
- 8.0
No data.
Red Hat Enterprise Linux 6 Supplementary
chromium-browser-0:80.0.3987.87-1.el6_10
Fixed · RHSA-2020:0514
Red Hat Enterprise Linux 7
libxslt-0:1.1.28-6.el7
Fixed · RHSA-2020:4005
Red Hat Enterprise Linux 8
libxslt-0:1.1.32-5.el8
Fixed · RHSA-2020:4464
Red Hat Enterprise Linux 8
libxslt-0:1.1.32-5.el8
Fixed · RHSA-2020:4464
Red Hat Enterprise Linux 5
libxslt
Out of support scope
Red Hat Enterprise Linux 6
libxslt
Out of support scope
Red Hat OpenStack Platform 10 (Newton)
libxslt
Will not fix
Red Hat OpenStack Platform 13 (Queens)
libxslt
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
libxslt
Will not fix
Red Hat Storage 3
libxslt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | chromium-browser-0:80.0.3987.87-1.el6_10 | Fixed | RHSA-2020:0514 |
| Red Hat Enterprise Linux 7 | libxslt-0:1.1.28-6.el7 | Fixed | RHSA-2020:4005 |
| Red Hat Enterprise Linux 8 | libxslt-0:1.1.32-5.el8 | Fixed | RHSA-2020:4464 |
| Red Hat Enterprise Linux 8 | libxslt-0:1.1.32-5.el8 | Fixed | RHSA-2020:4464 |
| Red Hat Enterprise Linux 5 | libxslt | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | libxslt | Out of support scope | n/a |
| Red Hat OpenStack Platform 10 (Newton) | libxslt | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | libxslt | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | libxslt | Will not fix | n/a |
| Red Hat Storage 3 | libxslt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack consumes fixes from the base Red Hat Enterprise Linux Operating System. Therefore the libxslt package provided by Red Hat OpenStack has been marked as 'will not fix'.
References (24)
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00010.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html vendor-advisoryx_refsource_SUSE
- http://www.openwall.com/lists/oss-security/2019/11/17/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0514 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-18197 Vendor Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15746 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15768 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15914 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1770768 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1901 Advisory
- https://github.com/advisories/GHSA-242x-7cm6-4w8j Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2019-18197.yml
- https://github.com/sparklemotion/nokogiri/blob/01ab95f3e37429ed8d3b380a8d2f73902eb325d9/CHANGELOG.md?plain=1#L934
- https://github.com/sparklemotion/nokogiri/issues/1943
- https://gitlab.gnome.org/GNOME/libxslt/commit/2232473733b7313d67de8836ea3b29eec6e8e285 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00037.html mailing-listx_refsource_MLISTThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-18197
- https://security.netapp.com/advisory/ntap-20191031-0004 x_refsource_CONFIRMThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200416-0004 x_refsource_CONFIRM
- https://usn.ubuntu.com/4164-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-18197
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISC
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub