CVE-2020-24977 is a medium-severity global buffer over-read vulnerability in libxml2 v2.9.10, affecting products from vendors like Debian, Fedora, and Oracle. This flaw, located in the xmlEncodeEntitiesInternal function, could allow an unauthenticated attacker to cause information disclosure or denial of service with low complexity. While there is no evidence of active exploitation, nor publicly available exploit code or significant community discussion, organizations using affected versions should apply the fix provided in commit 50f06b3e.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.9.10CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml2:2.9.10:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
Sep 8, 2020libxml2: Buffer overflow vulnerability in xmlEncodeEntitiesInternal() in entities.c
Sep 4, 2020