An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.
References
Link | Resource |
---|---|
https://github.com/michaelrsweet/mxml/issues/234 | Issue Tracking Third Party Advisory |
https://github.com/fouzhe/security/tree/master/mxml#heap-use-after-free-in-function-mxmlwalknext | Exploit Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N53IJHDYR5HVQLKH4J6B27OEQLGKSGY5/ | Mailing List Release Notes Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RNWF6BAU7S42O4LE4B74KIMHFE2HDNMI/ | Mailing List Third Party Advisory |
Information
Published : 2018-12-09 22:29
Updated : 2019-04-03 05:45
NVD link : CVE-2018-20005
Mitre link : CVE-2018-20005
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
msweet
- mini-xml
fedoraproject
- fedora