CVE-2018-20004: Debian Linux
High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.
An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the '<order type="real">' substring, as demonstrated by testmxml.
Affected products
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 28 only; version 29 only
- Mini-XML Project Mini-XML: version 2.12 only
Published 2018-12-10. Last modified 2026-06-17.