MGASA-2019-0159
Dashboard / Vulnerabilities / MGASA-2019-0159
MGASA-2019-0159
Summary: Updated mxml packages fix security vulnerabilities
Details: Updated mxml packages fix security vulnerabilities: An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the '<order type="real">' substring, as demonstrated by testmxml (CVE-2018-20004). An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc (CVE-2018-20005). In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted xml file, as demonstrated by mxmldoc (CVE-2018-20592). In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c (CVE-2018-20593).
References: https://advisories.mageia.org/MGASA-2019-0159.html, https://bugs.mageia.org/show_bug.cgi?id=24583, https://lists.fedoraproject.org/archives/list/[email protected]/thread/N53IJHDYR5HVQLKH4J6B27OEQLGKSGY5/
Affected packages
Package
Name: mxml
Purl: pkg:rpm/mageia/mxml?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
