First published: Tue Jan 21 2020(Updated: )
GNOME libxml2 could allow a remote attacker to obtain sensitive information, caused by a xmlSchemaValidateStream memory leak in xmlSchemaPreRun in xmlschemas.c. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbcs-httpd24-curl | <0:7.64.1-36.jbcs.el6 | 0:7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-httpd | <0:2.4.37-57.jbcs.el6 | 0:2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2 | <0:1.39.2-25.jbcs.el6 | 0:1.39.2-25.jbcs.el6 |
redhat/jbcs-httpd24-curl | <0:7.64.1-36.jbcs.el7 | 0:7.64.1-36.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <0:2.4.37-57.jbcs.el7 | 0:2.4.37-57.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2 | <0:1.39.2-25.jbcs.el7 | 0:1.39.2-25.jbcs.el7 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0:0.4.10-7.jbcs.el7 | 0:0.4.10-7.jbcs.el7 |
redhat/libxml2 | <0:2.9.1-6.el7.5 | 0:2.9.1-6.el7.5 |
redhat/libxml2 | <0:2.9.7-8.el8 | 0:2.9.7-8.el8 |
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
libxml2-devel | =2.9.10 | |
Debian Linux | =9.0 | |
NetApp Cloud Backup | ||
IBM Data ONTAP | ||
NetApp ONTAP Select Deploy | ||
NetApp Plug-in for Symantec NetBackup | ||
NetApp SMI-S Provider | ||
NetApp SnapDrive for Windows | ||
NetApp SteelStore Cloud Integrated Storage | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
NetApp H700S | ||
NetApp H300E | ||
NetApp H300E Firmware | ||
NetApp H500S Firmware | ||
NetApp H500e Firmware | ||
NetApp H700E | ||
NetApp H700E | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
Oracle Communications Cloud Native Core Network Function Cloud Native Environment | =1.10.0 | |
Oracle Enterprise Manager | =13.4.0.0 | |
Oracle Enterprise Manager | =13.5.0.0 | |
Oracle Enterprise Manager Ops Center | =12.4.0.0 | |
MySQL Workbench | <=8.0.26 | |
Oracle PeopleTools | =8.58 | |
Oracle Real User Experience Insight | =13.3.1.0 | |
Oracle Real User Experience Insight | =13.4.1.0 | |
Oracle Real User Experience Insight | =13.5.1.0 | |
SUSE Linux | =15.1 | |
Red Hat Fedora | =30 | |
Red Hat Fedora | =31 | |
Red Hat Fedora | =32 | |
NetApp Baseboard Management Controller Firmware | ||
NetApp Baseboard Management Controller H300S | ||
NetApp Baseboard Management Controller Firmware | ||
NetApp Baseboard Management Controller H500S | ||
NetApp Baseboard Management Controller Firmware | ||
NetApp Baseboard Management Controller H700S | ||
NetApp Baseboard Management Controller Firmware | ||
NetApp Baseboard Management Controller H300E | ||
NetApp Baseboard Management Controller H500E Firmware | ||
NetApp Baseboard Management Controller H500E Firmware | ||
NetApp Baseboard Management Controller H700E Firmware | ||
NetApp Baseboard Management Controller H700E Firmware | ||
NetApp Baseboard Management Controller Firmware | ||
NetApp Baseboard Management Controller H410S |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID is CVE-2019-20388.
The title of this vulnerability is 'xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.'
The severity of CVE-2019-20388 is high, with a severity value of 7.
The vulnerability allows for a memory leak in the xmlSchemaValidateStream function of libxml2, which can lead to a denial of service and impact system availability.
The affected software includes 'jbcs-httpd24-curl', 'jbcs-httpd24-httpd', 'jbcs-httpd24-nghttp2', 'jbcs-httpd24-openssl-pkcs11', 'libxml2', and their specific versions on different platforms.
More information about CVE-2019-20388 can be found on the following references: [link1], [link2], [link3].
The Common Weakness Enumeration (CWE) ID of CVE-2019-20388 is CWE-401.