CVE-2020-7595 describes an infinite loop vulnerability in the xmlStringLenDecodeEntities function of libxml2 version 2.9.10, triggered by a specific end-of-file condition. This flaw affects various products including Canonical, Debian, Fedora, NetApp, Oracle, Siemens, and xmlsoft. With a CVSS score of 7.5 (HIGH), it is a network-exploitable vulnerability with low attack complexity, requiring no user interaction or privileges, and leading to high availability impact. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has garnered some community discussion and media coverage, primarily from GitLab security releases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.9.10CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxml2:2.9.10:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2020-7595
Aug 11, 2020libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
Feb 24, 2020libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations
Jan 21, 2020xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
Jan 14, 2020