CVE-2019-20006

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2019-20006
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20006.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-20006
Published
2019-12-26T22:15:10Z
Modified
2024-06-30T13:01:14.070428Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxmlcharcontent puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), leading to a segmentation fault.

References

Affected packages

Debian:11 / mapcache

Package

Name
mapcache
Purl
pkg:deb/debian/mapcache?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.10.0-2
1.12.0~rc1-1~exp1
1.12.0-1~bpo11+1
1.12.0-1
1.12.1-1~bpo11+1
1.12.1-1
1.14.0-1~bpo11+1
1.14.0-1
1.14.0-2
1.14.0-2.1~exp1
1.14.0-3~exp1
1.14.0-3~exp2
1.14.0-3
1.14.0-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / mapcache

Package

Name
mapcache
Purl
pkg:deb/debian/mapcache?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.14.0-1
1.14.0-2
1.14.0-2.1~exp1
1.14.0-3~exp1
1.14.0-3~exp2
1.14.0-3
1.14.0-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / mapcache

Package

Name
mapcache
Purl
pkg:deb/debian/mapcache?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.14.0-1
1.14.0-2
1.14.0-2.1~exp1
1.14.0-3~exp1
1.14.0-3~exp2
1.14.0-3
1.14.0-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:11 / scilab

Package

Name
scilab
Purl
pkg:deb/debian/scilab?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.1.0+dfsg1-7
6.1.1+dfsg2-1
6.1.1+dfsg2-2
6.1.1+dfsg2-3
6.1.1+dfsg2-4
6.1.1+dfsg2-4+0.riscv64.1
6.1.1+dfsg2-5
6.1.1+dfsg2-6~exp0
6.1.1+dfsg2-6~exp1
6.1.1+dfsg2-6
6.1.1+dfsg2-7~exp0
6.1.1+dfsg2-7
6.1.1+dfsg2-8
6.1.1+dfsg2-9
6.1.1+dfsg2-10

2024.*

2024.0.0+dfsg-1
2024.0.0+dfsg-2
2024.0.0+dfsg-3
2024.0.0+dfsg-4
2024.0.0+dfsg-5
2024.0.0+dfsg-6

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / scilab

Package

Name
scilab
Purl
pkg:deb/debian/scilab?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.1.1+dfsg2-6
6.1.1+dfsg2-7~exp0
6.1.1+dfsg2-7
6.1.1+dfsg2-8
6.1.1+dfsg2-9
6.1.1+dfsg2-10

2024.*

2024.0.0+dfsg-1
2024.0.0+dfsg-2
2024.0.0+dfsg-3
2024.0.0+dfsg-4
2024.0.0+dfsg-5
2024.0.0+dfsg-6

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / scilab

Package

Name
scilab
Purl
pkg:deb/debian/scilab?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.1.1+dfsg2-6
6.1.1+dfsg2-7~exp0
6.1.1+dfsg2-7
6.1.1+dfsg2-8
6.1.1+dfsg2-9
6.1.1+dfsg2-10

2024.*

2024.0.0+dfsg-1
2024.0.0+dfsg-2
2024.0.0+dfsg-3
2024.0.0+dfsg-4
2024.0.0+dfsg-5
2024.0.0+dfsg-6

Ecosystem specific

{
    "urgency": "unimportant"
}