First published: Mon Dec 10 2018(Updated: )
An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
mini-xml | =2.12 | |
Fedora | =28 | |
Fedora | =29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20005 is classified as high severity due to the use-after-free vulnerability that can lead to memory corruption.
To fix CVE-2018-20005, update Mini-XML to the latest version that addresses the vulnerability.
CVE-2018-20005 affects Mini-XML version 2.12 and specific Fedora versions, including 28 and 29.
Exploiting CVE-2018-20005 may allow an attacker to execute arbitrary code or crash the application due to memory corruption.
Yes, a proof of concept demonstrating the use-after-free in Mini-XML has been made publicly known.