6.5
CVSSv3

CVE-2019-20198

Published: 31/12/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in ezXML 0.8.3 up to and including 0.8.6. The function ezxml_ent_ok() mishandles recursion, leading to stack consumption for a crafted XML file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ezxml project ezxml

Vendor Advisories

Debian Bug report logs - #989361 netcdf-parallel: Multiple security issues in ezxml Package: src:netcdf-parallel; Maintainer for src:netcdf-parallel is Alastair McKinstry <mckinstry@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 1 Jun 2021 19:57:04 UTC Severity: important Tags: security ...
Debian Bug report logs - #989360 netcdf: Multiple security issues in ezxml Package: src:netcdf; Maintainer for src:netcdf is Debian GIS Project <pkg-grass-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 1 Jun 2021 19:57:02 UTC Severity: important Tags: security Reply ...

Github Repositories

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

Cisco IOS XE implant scanning & network detection Network detection of CVE-2023-20198 exploitation and fingerprinting of post-exploitation of Cisco IOS XE devices CVE-2023-20198 Suricata network detection The suricata/ folder contains Suricata detection rules for exploitation of CVE-2023-20198 These rules monitor for a percent-encoded-percent which can be used to bypa