CVE-2018-20005: Use After Free
Published Dec 10, 2018
·Updated
An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.
Affected Software
3 affected components
Msweet Mini-xml=2.12
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Event History
Dec 10, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20005?
CVE-2018-20005 is classified as high severity due to the use-after-free vulnerability that can lead to memory corruption.
2
How do I fix CVE-2018-20005?
To fix CVE-2018-20005, update Mini-XML to the latest version that addresses the vulnerability.
3
Which versions of software are affected by CVE-2018-20005?
CVE-2018-20005 affects Mini-XML version 2.12 and specific Fedora versions, including 28 and 29.
4
What can an attacker achieve by exploiting CVE-2018-20005?
Exploiting CVE-2018-20005 may allow an attacker to execute arbitrary code or crash the application due to memory corruption.
5
Is there a known exploit for CVE-2018-20005?
Yes, a proof of concept demonstrating the use-after-free in Mini-XML has been made publicly known.