DescriptionThe mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
Overall state of this security issue: Resolved
This issue is currently rated as having low severity.
|National Vulnerability Database||SUSE|
|National Vulnerability Database|
- SUSE-SU-2017:3060-1, published Thu Nov 23 13:10:16 MST 2017
- openSUSE-SU-2017:0815-1, published Mon, 27 Mar 2017 21:07:53 +0200 (CEST)
List of released packages
|Product(s)||Fixed package version(s)||References|
|SUSE Linux Enterprise Software Development Kit 11 SP4|| ||Patchnames: |
|openSUSE Tumbleweed|| ||Patchnames: |
openSUSE Tumbleweed GA libmxml1
Status of this issue by product and package
Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification.
|SUSE Linux Enterprise Software Development Kit 11 SP4||mxml||Released|