CVE-2020-7595
published 2020-01-21CVE-2020-7595: xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
7.63%
93.9th percentile
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml2 | < libxml2 2.9.10+dfsg-2.1 (bookworm) | libxml2 2.9.10+dfsg-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_libxml2_2.9.10-2_on_cbl_mariner_1.0 | — | — |
| nokogiri | nokogiri | >= 0 < 1.10.8 | 1.10.8 |
| nokogiri | nokogiri | >= 0 < 1.11.4 | 1.11.4 |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | mysql_workbench | <= 8.0.26 | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | real_user_experience_insight | — | — |
| oracle | real_user_experience_insight | — | — |
| oracle | real_user_experience_insight | — | — |
| siemens | sinema_remote_connect_server | < 3.0 | 3.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
networkmanager: GRE & GRE6 protocol excessive trust
vendor_redhat·2025-01-14·CVSS 5.3
CVE-2024-7595 [MEDIUM] CWE-348 networkmanager: GRE & GRE6 protocol excessive trust
networkmanager: GRE & GRE6 protocol excessive trust
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors.
This can be considered similar to CVE-2020-10136.
An insecure configuration flaw was found in the GRE and GRE6 Protocols. When configured to not require authentication or filtering, this issue could allow a remote unauthenticated attacker to spoof packets or bypass access controls.
Statement: This vulnerability is rated as Low impact as it requires a known higher risk configuration. Multiple layers of defaults (packet forwarding and these specific protocols) are disable
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
CISA ICS
Siemens SINEMA Remote Connect Server
cisa_ics·2021-04-13·CVSS 7.5
[HIGH] Siemens SINEMA Remote Connect Server
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect Server
Last RevisedApril 13, 2021
Alert CodeICSA-21-103-08
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEMA Remote Connect Server
- Vulnerabilities: Missing Release of Resource after Effective Lifetime, Infinite Loop
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to cause a memory leak or an infinite loop situation resulting in a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The f
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: APM Mesh (libxml2) — CVE-2020-7595
vendor_oracle·2020-07-15·CVSS 7.5
CVE-2020-7595 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: APM Mesh (libxml2) — CVE-2020-7595
Oracle Oracle Enterprise Manager Risk Matrix: APM Mesh (libxml2) vulnerability
CVE: CVE-2020-7595
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Ubuntu
libxml2 vulnerabilities
vendor_ubuntu·2020-02-10·CVSS 7.5
CVE-2019-19956 [HIGH] libxml2 vulnerabilities
Title: libxml2 vulnerabilities
Summary: Several security issues were fixed in libxml2.
It was discovered that libxml2 incorrectly handled certain XML files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-19956, CVE-2020-7595)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations
vendor_redhat·2020-01-21·CVSS 7.5
CVE-2020-7595 [HIGH] CWE-835 libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations
libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
Package: libxml2 (Red Hat Enterprise Linux 5) - Out of support scope
Package: libxml2 (Red Hat Enterprise Linux 6) - Out of support scope
Microsoft
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
vendor_msrc·2020-01-14·CVSS 7.5
CVE-2020-7595 [HIGH] CWE-835 xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
R
Debian
CVE-2020-7595: libxml2 - xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in...
vendor_debian·2020·CVSS 7.5
CVE-2020-7595 [HIGH] CVE-2020-7595: libxml2 - xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in...
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
Scope: local
bookworm: resolved (fixed in 2.9.10+dfsg-2.1)
bullseye: resolved (fixed in 2.9.10+dfsg-2.1)
forky: resolved (fixed in 2.9.10+dfsg-2.1)
sid: resolved (fixed in 2.9.10+dfsg-2.1)
trixie: resolved (fixed in 2.9.10+dfsg-2.1)
OSV
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
osv·2021-05-17·CVSS 7.5
CVE-2019-20388 [HIGH] Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
### Summary
Nokogiri v1.11.4 updates the vendored libxml2 from v2.9.10 to v2.9.12 which addresses:
- [CVE-2019-20388](https://security.archlinux.org/CVE-2019-20388) (Medium severity)
- [CVE-2020-24977](https://security.archlinux.org/CVE-2020-24977) (Medium severity)
- [CVE-2021-3517](https://security.archlinux.org/CVE-2021-3517) (Medium severity)
- [CVE-2021-3518](https://security.archlinux.org/CVE-2021-3518) (Medium severity)
- [CVE-2021-3537](https://security.archlinux.org/CVE-2021-3537) (Low severity)
- [CVE-2021-3541](https://security.archlinux.org/CVE-2021-3541) (Low severity)
Note that two additional CVEs were addressed upstream but are not relevant to this release. [CVE-2021-3516](https://security.archlinux.or
GHSA
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
ghsa·2021-05-17·CVSS 7.5
CVE-2019-20388 [HIGH] Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
### Summary
Nokogiri v1.11.4 updates the vendored libxml2 from v2.9.10 to v2.9.12 which addresses:
- [CVE-2019-20388](https://security.archlinux.org/CVE-2019-20388) (Medium severity)
- [CVE-2020-24977](https://security.archlinux.org/CVE-2020-24977) (Medium severity)
- [CVE-2021-3517](https://security.archlinux.org/CVE-2021-3517) (Medium severity)
- [CVE-2021-3518](https://security.archlinux.org/CVE-2021-3518) (Medium severity)
- [CVE-2021-3537](https://security.archlinux.org/CVE-2021-3537) (Low severity)
- [CVE-2021-3541](https://security.archlinux.org/CVE-2021-3541) (Low severity)
Note that two additional CVEs were addressed upstream but are not relevant to this release. [CVE-2021-3516](https://security.archlinux.or
GHSA
libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
ghsa·2020-02-24
CVE-2020-7595 [HIGH] CWE-835 libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
The Nokogiri RubyGem has patched its vendored copy of libxml2 in order to prevent this issue from affecting nokogiri.
OSV
libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
osv·2020-02-24
CVE-2020-7595 [HIGH] libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
The Nokogiri RubyGem has patched its vendored copy of libxml2 in order to prevent this issue from affecting nokogiri.
OSV
libxml2 vulnerabilities
osv·2020-02-10·CVSS 7.5
CVE-2019-19956 [HIGH] libxml2 vulnerabilities
libxml2 vulnerabilities
It was discovered that libxml2 incorrectly handled certain XML files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-19956, CVE-2020-7595)
OSV
CVE-2020-7595: xmlStringLenDecodeEntities in parser
osv·2020-01-21·CVSS 7.5
CVE-2020-7595 [HIGH] CVE-2020-7595: xmlStringLenDecodeEntities in parser
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-7595 networkmanager: GRE & GRE6 protocol excessive trust
bugzilla·2024-10-08·CVSS 5.3
CVE-2024-7595 [MEDIUM] CVE-2024-7595 networkmanager: GRE & GRE6 protocol excessive trust
CVE-2024-7595 networkmanager: GRE & GRE6 protocol excessive trust
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.
Bugzilla
CVE-2020-7595 mingw-libxml2: libxml2: infinite loop in a certain end-of-file situation [epel-7]
bugzilla·2020-02-06·CVSS 7.5
CVE-2020-7595 [HIGH] CVE-2020-7595 mingw-libxml2: libxml2: infinite loop in a certain end-of-file situation [epel-7]
CVE-2020-7595 mingw-libxml2: libxml2: infinite loop in a certain end-of-file situation [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templat
Bugzilla
CVE-2020-7595 mingw-libxml2: libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations [fedora-all]
bugzilla·2020-02-06·CVSS 7.5
CVE-2020-7595 [HIGH] CVE-2020-7595 mingw-libxml2: libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations [fedora-all]
CVE-2020-7595 mingw-libxml2: libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2020-7595 libxml2: infinite loop in a certain end-of-file situation [fedora-all]
bugzilla·2020-02-06·CVSS 7.5
CVE-2020-7595 [HIGH] CVE-2020-7595 libxml2: infinite loop in a certain end-of-file situation [fedora-all]
CVE-2020-7595 libxml2: infinite loop in a certain end-of-file situation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2020-7595 libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations
bugzilla·2020-02-06·CVSS 7.5
CVE-2020-7595 [HIGH] CVE-2020-7595 libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations
CVE-2020-7595 libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
Reference and upstream commit:
https://gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c89076
Discussion:
Created libxml2 tracking bugs for this issue:
Affects: fedora-all [bug 1799787]
Created mingw-libxml2 tracking bugs for this issue:
Affects: epel-7 [bug 1799789]
Affects: fedora-all [bug 1799788]
---
This issue has been addressed in the following products:
JBoss Core Services on RHEL 6
JBoss Core Services on RHEL 7
Via RHSA-2020:2644 https://access.redhat.com/errata/RHSA-2020:2644
---
This issue has been addressed in the following products:
Red Hat JBoss Core Service
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00047.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-292794.pdfhttps://gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c89076https://lists.debian.org/debian-lts-announce/2020/09/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/545SPOI3ZPPNPX4TFRIVE4JVRTJRKULL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5R55ZR52RMBX24TQTWHCIWKJVRV6YAWI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JDPF3AAVKUAKDYFMFKSIQSVVS3EEFPQH/https://security.gentoo.org/glsa/202010-04https://security.netapp.com/advisory/ntap-20200702-0005/https://us-cert.cisa.gov/ics/advisories/icsa-21-103-08https://usn.ubuntu.com/4274-1/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00047.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-292794.pdfhttps://gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c89076https://lists.debian.org/debian-lts-announce/2020/09/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/545SPOI3ZPPNPX4TFRIVE4JVRTJRKULL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5R55ZR52RMBX24TQTWHCIWKJVRV6YAWI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JDPF3AAVKUAKDYFMFKSIQSVVS3EEFPQH/https://security.gentoo.org/glsa/202010-04https://security.netapp.com/advisory/ntap-20200702-0005/https://us-cert.cisa.gov/ics/advisories/icsa-21-103-08https://usn.ubuntu.com/4274-1/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-01-21
Published