AVG-922 log

Package mxml
Status Fixed
Severity High
Type multiple issues
Affected 2.12-1
Fixed 3.0-1
Current 3.3.1-1 [extra]
Ticket None
Created Mon Mar 11 15:51:10 2019
Issue Severity Remote Type Description
CVE-2018-20593 Medium No Arbitrary code execution
In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c.
CVE-2018-20592 Medium No Denial of service
In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability...
CVE-2018-20005 Medium No Arbitrary code execution
An issue has been found in Mini-XML (aka mxml) 2.12. It is a use- after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.
CVE-2018-20004 High Yes Arbitrary code execution
An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack- based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a...