Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-24977

Опубликовано: 04 сент. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxml2Out of support scope
Red Hat Enterprise Linux 6libxml2Out of support scope
Red Hat Enterprise Linux 7libxml2Will not fix
Red Hat JBoss Core Serviceslibxml2Not affected
Red Hat Enterprise Linux 8libxml2FixedRHSA-2021:159718.05.2021
Red Hat Enterprise Linux 8libxml2FixedRHSA-2021:159718.05.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1877788libxml2: Buffer overflow vulnerability in xmlEncodeEntitiesInternal() in entities.c

EPSS

Процентиль: 65%
0.00502
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

CVSS3: 6.5
nvd
больше 5 лет назад

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

CVSS3: 6.5
msrc
больше 5 лет назад

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

CVSS3: 6.5
debian
больше 5 лет назад

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerabil ...

suse-cvrf
больше 5 лет назад

Security update for libxml2

EPSS

Процентиль: 65%
0.00502
Низкий

6.5 Medium

CVSS3