CVE-2019-18197 is a use-after-free vulnerability in libxslt versions 1.1.33 and earlier, specifically within the xsltCopyText function, affecting products like Canonical, Debian, Linux, and XMLSoft. This flaw stems from a pointer variable not being reset, potentially leading to out-of-bounds writes or disclosure of uninitialized data. With a CVSS score of 7.5 (HIGH), exploitation requires high attack complexity and user interaction, but could result in high impact to confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, there is no known public exploit code (Metasploit, Nuclei, ExploitDB), and community discussion and media coverage are minimal, suggesting limited active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.33CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxslt:1.1.33:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.