cbcvebase.
CVE-2019-19956
published 2019-12-24

CVE-2019-19956: xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.

Affected

20 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlibxml2< libxml2 2.9.10+dfsg-2 (bookworm)libxml2 2.9.10+dfsg-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
oraclereal_user_experience_insight
siemenssinema_remote_connect_server< 3.03.0
xmlsoftlibxml2< 2.9.102.9.10
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-22.9.10+dfsg-2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-22.9.10+dfsg-2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-22.9.10+dfsg-2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-22.9.10+dfsg-2
xmlsoftlibxml2>= 0 < 2.9.3+dfsg1-1ubuntu0.72.9.3+dfsg1-1ubuntu0.7
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-6.1ubuntu1.32.9.4+dfsg1-6.1ubuntu1.3
xmlsoftlibxml2>= 0 < 2.9.1+dfsg1-3ubuntu4.13+esm12.9.1+dfsg1-3ubuntu4.13+esm1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH