CVE-2020-24977

Modified
Published: 03 Sept 2020, 23:20
Last modified:04 Aug 2024, 15:26

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.7% LOW
1% probability +0.19%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

03 Sept 2020, 23:20
Published
Vulnerability first disclosed
04 Aug 2024, 15:26
Last Modified
Vulnerability information updated

Description

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
  • v2.0MEDIUMScore: 6.4AV:N/AC:L/Au:N/C:P/I:N/A:P

EPSS Trends

Current EPSS score: 0.70% Percentile: 72%

Techniques & Countermeasures

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • debiandebian_linux

    9.0

  • fedoraprojectfedora

    31 | 32 | 33

  • netappactive_iq_unified_manager

    ≥ 7.3 | ≥ 9.5

  • netappclustered_data_ontap

    na

  • netappclustered_data_ontap_antivirus_connector

    na

  • netapphci_h410c_firmware

    na

  • netappinventory_collect_tool

    na

  • netappmanageability_software_development_kit

    na

  • netappsnapdrive

    na

  • opensuseleap

    15.1 | 15.2

  • oraclecommunications_cloud_native_core_network_function_cloud_native_environment

    1.10.0

  • oracleenterprise_manager_base_platform

    13.4.0.0 | 13.5.0.0

  • oracleenterprise_manager_ops_center

    12.4.0.0

  • oraclehttp_server

    12.2.1.3.0 | 12.2.1.4.0

  • oraclemysql_workbench

    ≤ 8.0.26

  • oraclepeoplesoft_enterprise_peopletools

    8.58

  • oraclereal_user_experience_insight

    13.4.1.0 | 13.5.1.0

  • xmlsoftlibxml2

    2.9.10

References (21)