xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
2020-01-21T23:15:13.867
2024-11-21T05:37:26.453
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | xmlsoft | libxml2 | 2.9.10 | Yes |
| Operating System | fedoraproject | fedora | 30 | Yes |
| Operating System | fedoraproject | fedora | 31 | Yes |
| Operating System | fedoraproject | fedora | 32 | Yes |
| Operating System | canonical | ubuntu_linux | 12.04 | Yes |
| Operating System | canonical | ubuntu_linux | 14.04 | Yes |
| Operating System | canonical | ubuntu_linux | 16.04 | Yes |
| Operating System | canonical | ubuntu_linux | 18.04 | Yes |
| Operating System | canonical | ubuntu_linux | 19.10 | Yes |
| Operating System | debian | debian_linux | 9.0 | Yes |
| Application | siemens | sinema_remote_connect_server | < 3.0 | Yes |
| Application | netapp | clustered_data_ontap | - | Yes |
| Application | netapp | smi-s_provider | - | Yes |
| Application | netapp | snapdrive | - | Yes |
| Application | netapp | steelstore_cloud_integrated_storage | - | Yes |
| Application | netapp | symantec_netbackup | - | Yes |
| Operating System | netapp | h300s_firmware | - | Yes |
| Hardware | netapp | h300s | - | No |
| Operating System | netapp | h500s_firmware | - | Yes |
| Hardware | netapp | h500s | - | No |
| Operating System | netapp | h700s_firmware | - | Yes |
| Hardware | netapp | h700s | - | No |
| Operating System | netapp | h300e_firmware | - | Yes |
| Hardware | netapp | h300e | - | No |
| Operating System | netapp | h500e_firmware | - | Yes |
| Hardware | netapp | h500e | - | No |
| Operating System | netapp | h700e_firmware | - | Yes |
| Hardware | netapp | h700e | - | No |
| Operating System | netapp | h410s_firmware | - | Yes |
| Hardware | netapp | h410s | - | No |
| Operating System | netapp | h410c_firmware | - | Yes |
| Hardware | netapp | h410c | - | No |
| Application | oracle | real_user_experience_insight | 13.3.1.0 | Yes |
| Application | oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.10.0 | Yes |
| Application | oracle | enterprise_manager_base_platform | 13.4.0.0 | Yes |
| Application | oracle | enterprise_manager_base_platform | 13.5.0.0 | Yes |
| Application | oracle | enterprise_manager_ops_center | 12.4.0.0 | Yes |
| Application | oracle | mysql_workbench | ≤ 8.0.26 | Yes |
| Application | oracle | peoplesoft_enterprise_peopletools | 8.58 | Yes |
| Application | oracle | real_user_experience_insight | 13.4.1.0 | Yes |
| Application | oracle | real_user_experience_insight | 13.5.1.0 | Yes |