### [CVE-2019-20198](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20198) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen) ### Description An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_ent_ok() mishandles recursion, leading to stack consumption for a crafted XML file. ### POC #### Reference - https://sourceforge.net/p/ezxml/bugs/20/ #### Github - https://github.com/fox-it/cisco-ios-xe-implant-detection - https://github.com/puckiestyle/cisco-ios-xe-implant-detection