mxml: CVE-2018-20004

Related Vulnerabilities: CVE-2018-20004  

Debian Bug report logs - #918007
mxml: CVE-2018-20004

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Wed, 2 Jan 2019 08:48:02 UTC

Severity: normal

Tags: patch, security, upstream

Found in version mxml/2.12-1

Fixed in version mxml/2.12-2

Done: Alastair McKinstry <mckinstry@debian.org>

Bug is archived. No further changes may be made.

Forwarded to https://github.com/michaelrsweet/mxml/issues/233

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, team@security.debian.org, Alastair McKinstry <mckinstry@debian.org>:
Bug#918007; Package src:mxml. (Wed, 02 Jan 2019 08:48:04 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, team@security.debian.org, Alastair McKinstry <mckinstry@debian.org>. (Wed, 02 Jan 2019 08:48:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: mxml: CVE-2018-20004
Date: Wed, 02 Jan 2019 09:45:10 +0100
Source: mxml
Version: 2.12-1
Severity: normal
Tags: patch security upstream
Forwarded: https://github.com/michaelrsweet/mxml/issues/233

Hi,

The following vulnerability was published for mxml.

CVE-2018-20004[0]:
| An issue has been found in Mini-XML (aka mxml) 2.12. It is a
| stack-based buffer overflow in mxml_write_node in mxml-file.c via
| vectors involving a double-precision floating point number and the
| '&lt;order type="real"&gt;' substring, as demonstrated by testmxml.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-20004
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20004
[1] https://github.com/michaelrsweet/mxml/issues/233

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Reply sent to Alastair McKinstry <mckinstry@debian.org>:
You have taken responsibility. (Wed, 02 Jan 2019 09:51:15 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Wed, 02 Jan 2019 09:51:15 GMT) (full text, mbox, link).


Message #10 received at 918007-close@bugs.debian.org (full text, mbox, reply):

From: Alastair McKinstry <mckinstry@debian.org>
To: 918007-close@bugs.debian.org
Subject: Bug#918007: fixed in mxml 2.12-2
Date: Wed, 02 Jan 2019 09:50:01 +0000
Source: mxml
Source-Version: 2.12-2

We believe that the bug you reported is fixed in the latest version of
mxml, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 918007@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alastair McKinstry <mckinstry@debian.org> (supplier of updated mxml package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 02 Jan 2019 09:21:23 +0000
Source: mxml
Binary: libmxml-dev libmxml-bin libmxml1
Architecture: source amd64
Version: 2.12-2
Distribution: unstable
Urgency: medium
Maintainer: Alastair McKinstry <mckinstry@debian.org>
Changed-By: Alastair McKinstry <mckinstry@debian.org>
Description:
 libmxml-bin - small XML parsing library (binaries)
 libmxml-dev - small XML parsing library (development)
 libmxml1   - small XML parsing library (runtime)
Closes: 918007
Changes:
 mxml (2.12-2) unstable; urgency=medium
 .
   * CVE-2018-20004: patch from upstream. Closes: #918007
   * Standards-Version: 4.3.0.
Checksums-Sha1:
 e5585cd6861b3ea9a467a34fb2016edcb1b5be26 1902 mxml_2.12-2.dsc
 7d0a119c1f9b3e855ee32f45f314973c64d6a189 12804 mxml_2.12-2.debian.tar.xz
 1c8b488531ee252d22d3df97ee8dbcc5d398cdbb 65032 libmxml-bin-dbgsym_2.12-2_amd64.deb
 c6ec3f8e04c4cce65e6e433e13b099eb76a0e600 36188 libmxml-bin_2.12-2_amd64.deb
 4cc0850f9b0578e5561c4b06eb1f8ab9605d0b63 41440 libmxml-dev_2.12-2_amd64.deb
 e53f62bb800f07c1a64f01e05c220ca09dcff114 45988 libmxml1-dbgsym_2.12-2_amd64.deb
 d946689752f2a27f060d531bcd2af427820ae29a 28248 libmxml1_2.12-2_amd64.deb
 8cf86a78dd4729e63a61429f2f964719833bebaf 6228 mxml_2.12-2_amd64.buildinfo
Checksums-Sha256:
 7bfcffb4257dde7a2c1ffe08925bc33d7c662f25fced1ad480c929deb7a08994 1902 mxml_2.12-2.dsc
 7e75c2226bb9f3b69c786fbf55c70624836393d8e8dd4a089987af60af68014b 12804 mxml_2.12-2.debian.tar.xz
 336d825775ba3433cc5b96c09bf0bd9229c7479e87c39243d9a8b9b038f39e0b 65032 libmxml-bin-dbgsym_2.12-2_amd64.deb
 fc32ac7f9743ac65e9d12b68f384031d12dec66577d279bd2e316374f95905cc 36188 libmxml-bin_2.12-2_amd64.deb
 bb5d763c1ffd23a1903554565b2a0ef891396e179cd2ce0459cb2b13d954679b 41440 libmxml-dev_2.12-2_amd64.deb
 9185b6d5ebe9b14a40d8a290f7895c9d16112f22333f0abc6641df33d984b63a 45988 libmxml1-dbgsym_2.12-2_amd64.deb
 159f3ad4dbd5dd58952bb77b5bb9f84525e70ab3a924c0291412d2e09299106b 28248 libmxml1_2.12-2_amd64.deb
 8813372d31571791183bc67c36075159518c76ad0f40dd7616ba0a2e704dd1a6 6228 mxml_2.12-2_amd64.buildinfo
Files:
 3141f9c4477cc9c0138558ef95da67b2 1902 libs optional mxml_2.12-2.dsc
 6af7568d1a35de5a99aef79e98143c39 12804 libs optional mxml_2.12-2.debian.tar.xz
 10e3ed7a6d24f7b266ef281665dc7a42 65032 debug optional libmxml-bin-dbgsym_2.12-2_amd64.deb
 931fe8441f02c5d228bfadb392d11153 36188 libs optional libmxml-bin_2.12-2_amd64.deb
 f1575cb2479b806199245922430e87e0 41440 libdevel optional libmxml-dev_2.12-2_amd64.deb
 7a20c8da3403843fe6513057f2989d51 45988 debug optional libmxml1-dbgsym_2.12-2_amd64.deb
 fc1f85cbfb671e8af8444f286ea273fd 28248 libs optional libmxml1_2.12-2_amd64.deb
 013620711f7f189293e1e3e948b73f17 6228 libs optional mxml_2.12-2_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEgjg86RZbNHx4cIGiy+a7Tl2a06UFAlwsg9oACgkQy+a7Tl2a
06UUYA/9HOjItEvvbgjaGcDqZmfUh4W73OrG48huiz4QcmSjHhc846LXfPxkZBqd
QzGyTSXhzPUkXAk65OHOhBDPIUIb27EO4fM+UsH4XykbgyNcaiadxKSmbeSl4dl/
t6BKe6lcR+UCv7yMMYY4Z0UDrOh4NuIU/G9FaLXKEUTiMhNrkGRM2/zp/itqBIFf
XP+/tRoF0hPojcJ7+QRxinrxWXYEJKO9+R/+MPTF7xFEXcScVU/2iVHXtPL2aEOc
MjD8IQlR/5HFrTNaJ3xKNHLcTvciyKDtrwz0d4adCsGYe9gjDkm0b1Uas2uSmtw7
PNbwp9Fo0htGNyTbF4Yl63HO9ViKNczgLPIwd5wZkWadUHc9miK7MlpsPhn7+9wE
tZ5TkeEsTZBtYRyaiY8CDeM+bRuHNFmCsofQl1OJa7z8wRUcOCu+NVlpqLM2CZXM
5ze57YdKJQpAvr+3NATOWDnX9nSZ+i1zcAV/Gs1zWoleNg2+Zoz1ivi75CFOb69L
SyYkjIawre2MKCQAaTw3DfnwsvYXsj8f3x5Urvi2zJaUDKMA0zYB+LxdCxkjuQGx
VklMvUaaCkK9tDAr6ZzP3Jah56xzEs420SBsVLXbTCxv/EXZLv28IXsxmmeqS6II
E/pWloOJJHO8NjmvL2HTJobchg+dauF/2gf7rjCWKgWyc7p1JmM=
=p5FD
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 04 Feb 2019 07:37:11 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 16:56:55 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.