libxml2: infinite loop in xmlStringLenDecodeEntities in some end-of-file situations
Published Jan 21, 2020
7.5
HIGHCVSS 3.1
EPSS 7.84%
Description
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
Affected products
No data.
Configuration 2
- 30
- 31
- 32
Configuration 3
- 12.04
- 14.04
- 16.04
- 18.04
- 19.10
Configuration 4
- 9.0
Configuration 5
- < 3.0
Configuration 6
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- 13.3.1.0
Configuration 16
- 1.10.0
- 13.4.0.0
- 13.5.0.0
- 12.4.0.0
- ≤ 8.0.26
- 8.58
- 13.4.1.0
- 13.5.1.0
No data.
JBoss Core Services on RHEL 6
jbcs-httpd24-curl-0:7.64.1-36.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-curl-0:7.64.1-36.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-pkcs11-0:0.4.10-7.jbcs.el7
Fixed · RHSA-2020:2644
Red Hat Enterprise Linux 7
libxml2-0:2.9.1-6.el7.5
Fixed · RHSA-2020:3996
Red Hat Enterprise Linux 8
libxml2-0:2.9.7-8.el8
Fixed · RHSA-2020:4479
Red Hat Enterprise Linux 8
libxml2-0:2.9.7-8.el8
Fixed · RHSA-2020:4479
Red Hat JBoss Core Services
libxml2
Fixed · RHSA-2020:2646
Red Hat OpenShift Do
openshiftdo/odo-init-image-rhel7:1.1.3-2
Fixed · RHSA-2021:0949
Red Hat Enterprise Linux 5
libxml2
Out of support scope
Red Hat Enterprise Linux 6
libxml2
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services on RHEL 6 | jbcs-httpd24-curl-0:7.64.1-36.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-curl-0:7.64.1-36.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-pkcs11-0:0.4.10-7.jbcs.el7 | Fixed | RHSA-2020:2644 |
| Red Hat Enterprise Linux 7 | libxml2-0:2.9.1-6.el7.5 | Fixed | RHSA-2020:3996 |
| Red Hat Enterprise Linux 8 | libxml2-0:2.9.7-8.el8 | Fixed | RHSA-2020:4479 |
| Red Hat Enterprise Linux 8 | libxml2-0:2.9.7-8.el8 | Fixed | RHSA-2020:4479 |
| Red Hat JBoss Core Services | libxml2 | Fixed | RHSA-2020:2646 |
| Red Hat OpenShift Do | openshiftdo/odo-init-image-rhel7:1.1.3-2 | Fixed | RHSA-2021:0949 |
| Red Hat Enterprise Linux 5 | libxml2 | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | libxml2 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (25)
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00047.html vendor-advisoryx_refsource_SUSEBroken Link
- https://access.redhat.com/security/cve/CVE-2020-7595 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1799786 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-292794.pdf x_refsource_CONFIRMThird Party Advisory
- https://github.com/advisories/GHSA-7553-jr98-vx47 Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2020-7595.yml
- https://github.com/sparklemotion/nokogiri/issues/1992
- https://gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c89076 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00009.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/545SPOI3ZPPNPX4TFRIVE4JVRTJRKULL/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5R55ZR52RMBX24TQTWHCIWKJVRV6YAWI/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JDPF3AAVKUAKDYFMFKSIQSVVS3EEFPQH/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/545SPOI3ZPPNPX4TFRIVE4JVRTJRKULL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5R55ZR52RMBX24TQTWHCIWKJVRV6YAWI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JDPF3AAVKUAKDYFMFKSIQSVVS3EEFPQH/
- https://nvd.nist.gov/vuln/detail/CVE-2020-7595
- https://security.gentoo.org/glsa/202010-04 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200702-0005/ x_refsource_CONFIRMThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-103-08 x_refsource_CONFIRMThird Party AdvisoryUS Government Resource
- https://usn.ubuntu.com/4274-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7595
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.