cbcvebase.
CVE-2019-20388
published 2020-01-21

CVE-2019-20388: xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibxml2< libxml2 2.9.10+dfsg-2.1 (bookworm)libxml2 2.9.10+dfsg-2.1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_libxml2_2.9.10-2_on_cbl_mariner_1.0
nokogirinokogiri>= 0 < 1.11.41.11.4
opensuseleap
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oracleenterprise_manager_ops_center
oraclemysql_workbench<= 8.0.26
oraclepeoplesoft_enterprise_peopletools
oraclereal_user_experience_insight
oraclereal_user_experience_insight
oraclereal_user_experience_insight
xmlsoftlibxml2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-2.12.9.10+dfsg-2.1
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-2.12.9.10+dfsg-2.1
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-2.12.9.10+dfsg-2.1
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-2.12.9.10+dfsg-2.1
xmlsoftlibxml2>= 0 < 2.9.4+dfsg1-6.1ubuntu1.42.9.4+dfsg1-6.1ubuntu1.4

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv9.1CRITICAL