PT-2020-6174 · Libxml2+8 · Libxml2+8

Published

2020-08-04

·

Updated

2026-03-13

·

CVE-2020-24977

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Libxml2 version 2.9.10
Description The issue is related to a global buffer over-read vulnerability in the xmlEncodeEntitiesInternal function at libxml2/entities.c in the Libxml2 library. This vulnerability allows a remote attacker to access confidential data and cause a denial of service.
Recommendations For Libxml2 version 2.9.10, update to a version that includes the fix committed in 50f06b3e to resolve the issue. As a temporary workaround, consider restricting access to the xmlEncodeEntitiesInternal function until a patch is available.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3218
ALT-PU-2020-3244
ALT-PU-2021-1579
ALT-PU-2021-2057
ALT-PU-2021-2997
ALT-PU-2021-3332
ALT-PU-2023-4266
ALT-PU-2024-7812
BDU:2021-03429
CESA-2021_1597
CVE-2020-24977
DLA-2369-1
MGASA-2021-0002
OPENSUSE-SU-2020:1430-1
OPENSUSE-SU-2020:1465-1
OPENSUSE-SU-2020_1430-1
OPENSUSE-SU-2020_1465-1
OPENSUSE-SU-2024:11016-1
OPENSUSE-SU-2024:11340-1
OPENSUSE-SU-2024:11912-1
OPENSUSE-SU-2024:13165-1
OPENSUSE-SU-2024:14174-1
OPENSUSE-SU-2025:14697-1
OPENSUSE-SU-2026:10356-1
RHSA-2021:1597
RHSA-2021_1597
RLSA-2021:1597
SUSE-SU-2020:2609-1
SUSE-SU-2020:2612-1
SUSE-SU-2020_2612-1
SUSE-SU-2021:14729-1
SUSE-SU-2021_14729-1
USN-4991-1

Affected Products

Alt Linux
Astra Linux
Centos
Libxml2
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu