MEDIUM · 6.5

CVE-2020-24977

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

Vulnerability Description

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
XmlsoftLibxml22.9.10
DebianDebian Linux9.0
FedoraprojectFedora31
OpensuseLeap15.1
NetappActive Iq Unified Manager>= 7.3
NetappClustered Data Ontap-
NetappClustered Data Ontap Antivirus Connector-
NetappInventory Collect Tool-
NetappManageability Software Development Kit-
NetappSnapdrive-
NetappHci H410C Firmware-
NetappHci H410C-
OracleCommunications Cloud Native Core Network Function Cloud Native Environment1.10.0
OracleEnterprise Manager Base Platform13.4.0.0
OracleEnterprise Manager Ops Center12.4.0.0
OracleHttp Server12.2.1.3.0
OracleMysql Workbench<= 8.0.26
OraclePeoplesoft Enterprise Peopletools8.58
OracleReal User Experience Insight13.4.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-24977?

CVE-2020-24977 is a vulnerability with a CVSS score of 6.5 (MEDIUM). GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

How severe is CVE-2020-24977?

CVE-2020-24977 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-24977?

Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxml2, Debian Debian Linux, Fedoraproject Fedora, Opensuse Leap, Netapp Active Iq Unified Manager.