Vulnerabilities > CVE-2019-20006 - Use After Free vulnerability in Ezxml Project Ezxml
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), leading to a segmentation fault.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |