CVE-2020-24977

Description

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS Score
Exploitation Probability
0.502

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 12.2.1.3.0Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 12.2.1.4.0Windows
(RHSA-2021:1597) libxml2 security update libxml2-2.9.7-9.el8.i686.rpmLinux
(RHSA-2021:1597) libxml2 security update libxml2-2.9.7-9.el8.x86_64.rpmLinux
(RHSA-2021:1597) libxml2 security update libxml2-debugsource-2.9.7-9.el8.i686.rpmLinux
(RHSA-2021:1597) libxml2 security update libxml2-debugsource-2.9.7-9.el8.x86_64.rpmLinux
(RHSA-2021:1597) libxml2 security update libxml2-devel-2.9.7-9.el8.i686.rpmLinux
(RHSA-2021:1597) libxml2 security update libxml2-devel-2.9.7-9.el8.x86_64.rpmLinux
(RHSA-2021:1597) libxml2 security update python3-libxml2-2.9.7-9.el8.x86_64.rpmLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-6.3ubuntu0.1_i386.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-6.3ubuntu0.1_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.4+dfsg1-6.1ubuntu1.4_i386.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.4+dfsg1-6.1ubuntu1.4_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-5ubuntu0.20.04.1_i386.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-5ubuntu0.20.04.1_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-5ubuntu0.20.10.2_i386.debLinux
GNOME XML library (USN-4991-1) libxml2_2.9.10+dfsg-5ubuntu0.20.10.2_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-6.3ubuntu0.1_i386.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-6.3ubuntu0.1_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.4+dfsg1-6.1ubuntu1.4_i386.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.4+dfsg1-6.1ubuntu1.4_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.1_i386.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-5ubuntu0.20.04.1_amd64.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-5ubuntu0.20.10.2_i386.debLinux
GNOME XML library (USN-4991-1) libxml2-utils_2.9.10+dfsg-5ubuntu0.20.10.2_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234