numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxslt | Sep 20, 2017 | Jun 5, 2016 |
| Apple Itunes | — | Upgrade Apple iTunes to the latest version | Dec 16, 2016 | Jun 5, 2016 |
| Apple Osx Libxslt | — | Apply OS X security update 2016-004Upgrade macOS to the latest version | Nov 11, 2016 | Jun 5, 2016 |
| Debian | — | Upgrade libxslt | Jun 5, 2016 | Jun 5, 2016 |
| Freebsd | — | Upgrade libxslt | Dec 10, 2025 | Jun 20, 2016 |
| Gentoo Linux | — | Upgrade www-client/chromium. | Oct 30, 2017 | Jun 5, 2016 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Jun 9, 2016 | May 25, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libxslt-pythonUpgrade libxsltUpgrade libxslt-devel | Dec 4, 2019 | Jun 5, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libxslt-pythonUpgrade libxslt-develUpgrade libxslt | Dec 18, 2019 | Jun 5, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libxslt-pythonUpgrade libxsltUpgrade libxslt-devel | Nov 19, 2019 | Jun 5, 2016 |
| Oracle Solaris | — | Upgrade library/libxslt to version 1.1.33-0.175.3.36.0.19.0 on Solaris 11.3Upgrade library/python/libxsl-27 to version 1.1.33-11.4.8.0.1.1.0 on Solaris 11.4Upgrade library/libxslt to version 1.1.33-11.4.8.0.1.1.0 on Solaris 11.4Upgrade library/python/libxsl-27 to version 1.1.33-0.175.3.36.0.19.0 on Solaris 11.3 | Apr 17, 2019 | Jun 5, 2016 |
| Redhat_linux | — | No solution existsUpgrade chromium-browserUpgrade chromium-browser-debuginfo | Jun 1, 2016 | Jun 1, 2016 |
| Suse | — | Upgrade chromium | May 31, 2016 | May 28, 2016 |
| Ubuntu | — | Upgrade liboxideqtcore0Upgrade libxslt1.1 | Jun 6, 2016 | Jun 5, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub