First published: Thu Sep 03 2020(Updated: )
GNOME libxml2 is vulnerable to a buffer overflow, caused by improper bounds checking by the xmlEncodeEntitiesInternal function in libxml2/entities.c. By persuading a victim to open a specially-crafted file, a remote attacker could overflow a buffer and execute arbitrary code on the system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xmlsoft Libxml2 | =2.9.10 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Netapp Active Iq Unified Manager Windows | >=7.3 | |
Netapp Active Iq Unified Manager Vmware Vsphere | >=9.5 | |
NetApp Clustered Data ONTAP | ||
Netapp Clustered Data Ontap Antivirus Connector | ||
Netapp Inventory Collect Tool | ||
Netapp Manageability Software Development Kit | ||
Netapp Snapdrive Unix | ||
Netapp Snapdrive Windows | ||
Netapp Hci H410c Firmware | ||
Netapp Hci H410c | ||
Oracle Communications Cloud Native Core Network Function Cloud Native Environment | =1.10.0 | |
Oracle Enterprise Manager Base Platform | =13.4.0.0 | |
Oracle Enterprise Manager Base Platform | =13.5.0.0 | |
Oracle Enterprise Manager Ops Center | =12.4.0.0 | |
Oracle HTTP Server | =12.2.1.3.0 | |
Oracle HTTP Server | =12.2.1.4.0 | |
Oracle Mysql Workbench | <=8.0.26 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
Oracle Real User Experience Insight | =13.4.1.0 | |
Oracle Real User Experience Insight | =13.5.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.2.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-24977.
The severity of CVE-2020-24977 is high with a CVSS score of 7.8.
The affected software includes IBM Security Verify Access, Xmlsoft Libxml2, Debian Debian Linux, Fedoraproject Fedora, openSUSE Leap, NetApp products, Apple watchOS, Apple iPadOS, Apple macOS Big Sur, Oracle products, and others.
CVE-2020-24977 exploits a buffer overflow vulnerability in the xmlEncodeEntitiesInternal function in libxml2/entities.c by persuading a victim to open a specially-crafted file, allowing a remote attacker to execute arbitrary code on the system.
Yes, a fix is available for CVE-2020-24977. It is recommended to update to the latest version of the affected software or apply the necessary patches provided by the vendor.