First published: Tue Jan 21 2020(Updated: )
GNOME libxml2 is vulnerable to a denial of service, caused by an error in xmlStringLenDecodeEntities in parser.c. An attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbcs-httpd24-curl | <0:7.64.1-36.jbcs.el6 | 0:7.64.1-36.jbcs.el6 |
redhat/jbcs-httpd24-httpd | <0:2.4.37-57.jbcs.el6 | 0:2.4.37-57.jbcs.el6 |
redhat/jbcs-httpd24-nghttp2 | <0:1.39.2-25.jbcs.el6 | 0:1.39.2-25.jbcs.el6 |
redhat/jbcs-httpd24-curl | <0:7.64.1-36.jbcs.el7 | 0:7.64.1-36.jbcs.el7 |
redhat/jbcs-httpd24-httpd | <0:2.4.37-57.jbcs.el7 | 0:2.4.37-57.jbcs.el7 |
redhat/jbcs-httpd24-nghttp2 | <0:1.39.2-25.jbcs.el7 | 0:1.39.2-25.jbcs.el7 |
redhat/jbcs-httpd24-openssl-pkcs11 | <0:0.4.10-7.jbcs.el7 | 0:0.4.10-7.jbcs.el7 |
redhat/libxml2 | <0:2.9.1-6.el7.5 | 0:2.9.1-6.el7.5 |
redhat/libxml2 | <0:2.9.7-8.el8 | 0:2.9.7-8.el8 |
debian/libxml2 | 2.9.10+dfsg-6.7+deb11u4 2.9.10+dfsg-6.7+deb11u5 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3 2.12.7+dfsg-3 | |
Siemens SINEMA Remote Connect | <3.0 | 3.0 |
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
libxml2 | =2.9.10 | |
Fedora | =30 | |
Fedora | =31 | |
Fedora | =32 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.10 | |
Debian | =9.0 | |
Siemens SINEMA Remote Connect | <3.0 | |
IBM Data ONTAP | ||
netapp smi-s provider | ||
netapp snapdrive windows | ||
NetApp SteelStore | ||
Symantec NetBackup | ||
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h300e firmware | ||
netapp h300e | ||
All of | ||
netapp h500e firmware | ||
netapp h500e | ||
All of | ||
netapp h700e firmware | ||
netapp h700e | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
oracle real user experience insight | =13.3.1.0 | |
oracle communications cloud native core network function cloud native environment | =1.10.0 | |
Oracle Enterprise Manager Base Platform | =13.4.0.0 | |
Oracle Enterprise Manager Base Platform | =13.5.0.0 | |
Oracle Enterprise Manager Ops Center | =12.4.0.0 | |
oracle mysql workbench | <=8.0.26 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
oracle real user experience insight | =13.4.1.0 | |
oracle real user experience insight | =13.5.1.0 | |
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h300e firmware | ||
netapp h300e | ||
netapp h500e firmware | ||
netapp h500e | ||
netapp h700e firmware | ||
netapp h700e | ||
netapp h410s firmware | ||
netapp h410s | ||
netapp h410c firmware | ||
netapp h410c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of CVE-2020-7595 is high.
The affected software version of CVE-2020-7595 is libxml2 2.9.10.
CVE-2020-7595 causes an infinite loop in a certain end-of-file situation in libxml2 2.9.10.
The recommended remedy for CVE-2020-7595 is to update to version 2.9.1-6.el7.5 or 2.9.7-8.el8 of libxml2.
Yes, there are references available for CVE-2020-7595. Please refer to the following links: https://gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c89076 and https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1799787 and https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1799789.