PT-2019-5529 · Xmlsoft+5 · Libxml2+5

Published

2019-12-12

·

Updated

2026-03-13

·

CVE-2020-7595

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libxml2 version 2.9.10
Description The issue is related to the xmlStringLenDecodeEntities function in the libxml2 library, which can lead to an infinite loop under certain end-of-file conditions. This could allow a remote attacker to cause a denial of service. The Nokogiri RubyGem has patched its vendored copy of libxml2 to prevent this issue from affecting nokogiri.
Recommendations For libxml2 version 2.9.10, consider disabling the xmlStringLenDecodeEntities function as a temporary workaround until a patch is available. Restrict access to the parser.c file to minimize the risk of exploitation. Avoid using the xmlStringLenDecodeEntities function in certain end-of-file situations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3218
ALT-PU-2020-3244
ALT-PU-2021-1579
ALT-PU-2021-2057
ALT-PU-2021-3332
BDU:2020-03623
CESA-2020_3996
CESA-2020_4479
CVE-2020-7595
DLA-2369-1
GHSA-7553-JR98-VX47
MGASA-2020-0101
OPENSUSE-SU-2020:0681-1
OPENSUSE-SU-2020_0681-1
OPENSUSE-SU-2024:11016-1
OPENSUSE-SU-2024:11340-1
OPENSUSE-SU-2024:11912-1
OPENSUSE-SU-2024:13165-1
OPENSUSE-SU-2024:14174-1
OPENSUSE-SU-2025:14697-1
OPENSUSE-SU-2026:10356-1
RHSA-2020:2644
RHSA-2020:3996
RHSA-2020:4479
RHSA-2020_3996
RHSA-2020_4479
SUSE-SU-2020:0640-1
SUSE-SU-2020:1299-1
SUSE-SU-2020:2609-1
SUSE-SU-2021:14729-1
SUSE-SU-2021_14729-1
USN-4274-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libxml2