Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
References
| Link | Resource |
|---|---|
| https://bugs.chromium.org/p/chromium/issues/detail?id=930663 | Exploit Vendor Advisory |
| https://gitlab.gnome.org/GNOME/libxslt/commit/08b62c25871b38d5d573515ca8a065b4b8f64f6b | Patch Vendor Advisory |
Configurations
Information
Published : 2019-12-11 01:15
Updated : 2021-07-21 11:39
NVD link : CVE-2019-5815
Mitre link : CVE-2019-5815
JSON object : View
Products Affected
xmlsoft
- libxslt
CWE
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
