Lucene search

K
osvGoogleOSV:CVE-2019-18197
HistoryOct 18, 2019 - 9:15 p.m.

CVE-2019-18197

2019-10-1821:15:10
Google
osv.dev
6

7.2 High

AI Score

Confidence

Low

0.023 Low

EPSS

Percentile

89.8%

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn’t reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

References