Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2019-5815

Published: December 11, 2019Last modified: November 8, 2023

Description

Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibxsltNot affected (1.1.37-r1)
StreamlibxsltNot affected (1.1.38-r1)

References

ON THIS PAGE