Lucene search

K
osvGoogleOSV:GHSA-4HM9-844J-JMXP
HistoryMay 24, 2022 - 4:49 p.m.

Uninitialized read in Nokogiri gem

2022-05-2416:49:06
Google
osv.dev
14
uninitialized read
libxslt 1.1.33
nokogiri gem
attacker discern
software vulnerability

EPSS

0.008

Percentile

81.7%

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

References