MGASA-2017-0103
Dashboard / Vulnerabilities / MGASA-2017-0103
Summary: Updated mxml packages fix security vulnerability
Details: Two stack exhaustion issues based on uncontrolled recursion were found in mxml. A maliciously crafted xml file can cause the application to crash. * Recursion using mxmlDelete at mxml-node.c:217 (reproducer is stack-exhaustion-1.xml CVE-2016-4570). * Recursion using mxml_write_node at mxml-file.c:2739 (reproducer is stack-exhaustion-2.xml CVE-2016-4571).
References: https://advisories.mageia.org/MGASA-2017-0103.html, https://bugs.mageia.org/show_bug.cgi?id=20593, https://bugzilla.redhat.com/show_bug.cgi?id=1334648, https://lists.opensuse.org/opensuse-updates/2017-03/msg00081.html, http://seclists.org/oss-sec/2016/q2/276
Affected packages
Package
Name: mxml
Purl: pkg:rpm/mageia/mxml?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
