In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted xml file, as demonstrated by mxmldoc.
{ "binaries": [ { "binary_version": "3.3-1", "binary_name": "libmxml-dev" }, { "binary_version": "3.3-1", "binary_name": "libmxml1" } ] }
{ "binaries": [ { "binary_version": "3.3.1-1build1", "binary_name": "libmxml-dev" }, { "binary_version": "3.3.1-1build1", "binary_name": "libmxml1" } ] }
{ "binaries": [ { "binary_version": "2.9-0ubuntu2", "binary_name": "libmxml-dev" }, { "binary_version": "2.9-0ubuntu2", "binary_name": "libmxml1" } ] }
{ "binaries": [ { "binary_version": "2.10-1", "binary_name": "libmxml-bin" }, { "binary_version": "2.10-1", "binary_name": "libmxml-dev" }, { "binary_version": "2.10-1", "binary_name": "libmxml1" } ] }
{ "binaries": [ { "binary_version": "3.1-1", "binary_name": "libmxml-dev" }, { "binary_version": "3.1-1", "binary_name": "libmxml1" } ] }