mxml

Link package | bugs open | bugs closed | Wiki | GitHub | web search
Description A small XML parsing library
Version 3.3.1-1 [extra]

Resolved

Group Affected Fixed Severity Status Ticket
AVG-922 2.12-1 3.0-1 High Fixed
Issue Group Severity Remote Type Description
CVE-2018-20593 AVG-922 Medium No Arbitrary code execution
In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c.
CVE-2018-20592 AVG-922 Medium No Denial of service
In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability...
CVE-2018-20005 AVG-922 Medium No Arbitrary code execution
An issue has been found in Mini-XML (aka mxml) 2.12. It is a use- after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.
CVE-2018-20004 AVG-922 High Yes Arbitrary code execution
An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack- based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a...