Bugzilla – Bug 1118927
VUL-0: CVE-2018-20005: mxml: use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.
Last modified: 2020-10-21 09:22:12 UTC
CVE-2018-20005 An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20005 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20005
https://github.com/fouzhe/security/tree/master/mxml#heap-use-after-free-in-function-mxmlwalknext https://github.com/michaelrsweet/mxml/issues/234
Created attachment 792276 [details] heap-use-after-free_mxmlWalkNext QA REPRODUCER: mxmldoc ~/Downloads/heap-use-after-free_mxmlWalkNext >/dev/null Speicherzugriffsfehler should not crash
No upstream fix atm.
Still no upstream fix.
https://build.opensuse.org/request/show/816865 https://build.opensuse.org/request/show/816861