#VU46737 Out-of-bounds read in Libxml2 - CVE-2020-24977
Published: September 4, 2020 / Updated: May 14, 2021
Libxml2
Gnome Development Team
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the xmlEncodeEntitiesInternal() function in libxml2/entities.c in libxml2. A remote attacker can pas specially crafted XML data to the affected application, trigger out-of-bounds read error and read contents of memory on the system.