An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, performs incorrect memory handling, leading to a heap-based buffer over-read in the "normalize line endings" feature.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-12-31T20:30:45

Updated: 2024-08-05T02:39:08.875Z

Reserved: 2019-12-31T00:00:00

Link: CVE-2019-20200

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-12-31T21:15:11.897

Modified: 2020-01-06T19:33:38.380

Link: CVE-2019-20200

cve-icon Redhat

No data.