cbcvebase.
CVE-2020-24977
published 2020-09-04

CVE-2020-24977: GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in…

medium6.5CVSS 3.1
AVNACLPRNUINSUCLINAL
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibxml2< libxml2 2.9.10+dfsg-6.2 (bookworm)libxml2 2.9.10+dfsg-6.2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccm1_libxml2_2.9.10-3_on_cbl_mariner_1.0
netappactive_iq_unified_manager>= 7.3
netappactive_iq_unified_manager>= 9.5
nokogirinokogiri>= 0 < 1.11.41.11.4
opensuseleap
opensuseleap
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oracleenterprise_manager_ops_center
oraclehttp_server
oraclehttp_server
oraclemysql_workbench<= 8.0.26
oraclepeoplesoft_enterprise_peopletools
oraclereal_user_experience_insight
oraclereal_user_experience_insight
xmlsoftlibxml2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.22.9.10+dfsg-6.2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.22.9.10+dfsg-6.2
xmlsoftlibxml2>= 0 < 2.9.10+dfsg-6.22.9.10+dfsg-6.2

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
ghsa7.5HIGH
osv9.1CRITICAL