CVE-2020-13577: Null Pointer Dereference
Published Feb 10, 2021
·Updated
A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
3 affected components
Genivia gSOAP=2.8.107
fedoraproject fedora=33
fedoraproject fedora=34
Event History
Feb 10, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-13577?
CVE-2020-13577 refers to a denial-of-service vulnerability in the WS-Security plugin functionality of Genivia gSOAP 2.8.107.
2
What is the severity of CVE-2020-13577?
CVE-2020-13577 has a severity rating of 7.5 (high).
3
How does CVE-2020-13577 impact Genivia gSOAP?
CVE-2020-13577 can lead to denial of service in Genivia gSOAP 2.8.107 when a specially crafted SOAP request is sent.
4
What software versions are affected by CVE-2020-13577?
Genivia gSOAP 2.8.107, Fedoraproject Fedora 33, and Fedoraproject Fedora 34 are affected by CVE-2020-13577.
5
How can CVE-2020-13577 be fixed?
To fix CVE-2020-13577, it is recommended to update Genivia gSOAP to a version that is not vulnerable.