First published: Tue Jan 21 2020(Updated: )
GNOME libxml2 could allow a remote attacker to obtain sensitive information, caused by a xmlSchemaValidateStream memory leak in xmlSchemaPreRun in xmlschemas.c. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbcs-httpd24-curl | <0:7.64.1-36.jbcs.el6 | 0:7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-httpd | <0:2.4.37-57.jbcs.el6 | 0:2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2 | <0:1.39.2-25.jbcs.el6 | 0:1.39.2-25.jbcs.el6 |
redhat/jbcs-httpd24-curl | <0:7.64.1-36.jbcs.el7 | 0:7.64.1-36.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <0:2.4.37-57.jbcs.el7 | 0:2.4.37-57.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2 | <0:1.39.2-25.jbcs.el7 | 0:1.39.2-25.jbcs.el7 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0:0.4.10-7.jbcs.el7 | 0:0.4.10-7.jbcs.el7 |
redhat/libxml2 | <0:2.9.1-6.el7.5 | 0:2.9.1-6.el7.5 |
redhat/libxml2 | <0:2.9.7-8.el8 | 0:2.9.7-8.el8 |
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
libxml2 | =2.9.10 | |
Debian | =9.0 | |
netapp cloud backup | ||
NetApp Clustered Data ONTAP | ||
NetApp ONTAP Select Deploy | ||
netapp plug-in for symantec netbackup | ||
netapp smi-s provider | ||
netapp snapdrive windows | ||
NetApp SteelStore | ||
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h300e firmware | ||
netapp h300e | ||
netapp h500e firmware | ||
netapp h500e | ||
netapp h700e firmware | ||
netapp h700e | ||
netapp h410s firmware | ||
netapp h410s | ||
oracle communications cloud native core network function cloud native environment | =1.10.0 | |
Oracle Enterprise Manager Base Platform | =13.4.0.0 | |
Oracle Enterprise Manager Base Platform | =13.5.0.0 | |
Oracle Enterprise Manager Ops Center | =12.4.0.0 | |
oracle mysql workbench | <=8.0.26 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
oracle real user experience insight | =13.3.1.0 | |
oracle real user experience insight | =13.4.1.0 | |
oracle real user experience insight | =13.5.1.0 | |
openSUSE | =15.1 | |
Fedora | =30 | |
Fedora | =31 | |
Fedora | =32 | |
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h300s | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h500s | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h700s | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h300e | ||
netapp baseboard management controller h500e firmware | ||
netapp baseboard management controller h500e | ||
netapp baseboard management controller h700e firmware | ||
netapp baseboard management controller h700e | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h410s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID is CVE-2019-20388.
The title of this vulnerability is 'xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.'
The severity of CVE-2019-20388 is high, with a severity value of 7.
The vulnerability allows for a memory leak in the xmlSchemaValidateStream function of libxml2, which can lead to a denial of service and impact system availability.
The affected software includes 'jbcs-httpd24-curl', 'jbcs-httpd24-httpd', 'jbcs-httpd24-nghttp2', 'jbcs-httpd24-openssl-pkcs11', 'libxml2', and their specific versions on different platforms.
More information about CVE-2019-20388 can be found on the following references: [link1], [link2], [link3].
The Common Weakness Enumeration (CWE) ID of CVE-2019-20388 is CWE-401.