HIGH · 7.5

CVE-2020-7595

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

Vulnerability Description

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
XmlsoftLibxml22.9.10
FedoraprojectFedora30
CanonicalUbuntu Linux12.04
DebianDebian Linux9.0
SiemensSinema Remote Connect Server< 3.0
NetappClustered Data Ontap-
NetappSmi-S Provider-
NetappSnapdrive-
NetappSteelstore Cloud Integrated Storage-
NetappSymantec Netbackup-
NetappH300S Firmware-
NetappH300S-
NetappH500S Firmware-
NetappH500S-
NetappH700S Firmware-
NetappH700S-
NetappH300E Firmware-
NetappH300E-
NetappH500E Firmware-
NetappH500E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-7595?

CVE-2020-7595 is a vulnerability with a CVSS score of 7.5 (HIGH). xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

How severe is CVE-2020-7595?

CVE-2020-7595 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-7595?

Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxml2, Fedoraproject Fedora, Canonical Ubuntu Linux, Debian Debian Linux, Siemens Sinema Remote Connect Server.