Out-of-bounds read in Libxml2 - CVE-2020-24977
Published: September 4, 2020 / Updated: May 14, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the xmlEncodeEntitiesInternal() function in libxml2/entities.c in libxml2. A remote attacker can pas specially crafted XML data to the affected application, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
HPE B-series SN6750B Fibre Channel Switch
HPE SN8700B 4-slot SAN Director Switch
Brocade 32Gb Fibre Channel SAN Switch for HPE Synergy
HPE SN8700B 8-slot SAN Director Switch
HPE SN8600B 4-slot SAN Director Switch
HPE SN8600B 8-slot SAN Director Switch
HPE B-series SN2600B SAN Extension Switch
HPE B-series SN4700B SAN Extension Switch
HPE B-series SN6600B Fibre Channel Switch
HPE B-series SN6650B Fibre Channel Switch
HPE B-series SN6700B Fibre Channel Switch
HPE B-series SN3600B Fibre Channel Switch
IBM RackSwitch G7028
IBM RackSwitch G8124E
IBM RackSwitch G8124
IBM RackSwitch G8052
Gentoo Linux
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
Ubuntu
Opensuse
Fedora
Brocade Fabric OS
cflinuxfs3
APM Edge
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
Cloud Pak for Security (CP4S)
Red Hat OpenShift Jaeger
libxml2 (Alpine package)
libxml2 (Red Hat package)
libxml2-32bit
libxml2-python
libxml2-doc
libxml2
libxml2-debuginfo
libxml2-debugsource
libxml2-python-debuginfo
libxml2-python-debugsource
libxml2 (Ubuntu package)
libxml2-utils (Ubuntu package)
mingw-libxml2
IBM Security Verify Access
RTU500 CMU
Oracle HTTP Server
Web Terminal
How to mitigate CVE-2020-24977
cflinuxfs3 - update to 0.245.0
APM Edge - update to 4.0
Red Hat OpenShift Serverless - update to 1.16.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
libxml2 (Alpine package) - update to 2.9.10-r5
libxml2 (Red Hat package) - update to 2.9.7-9.el8
RTU500 CMU - addressed in versions 12.0.14.0, 12.2.11.0, 12.4.11, 12.6.7, 12.7.2, 13.2.3
Web Terminal - update to 1.3
libxml2-32bit - update to 2.7.6-0.77.36.1
libxml2-python - update to 2.7.6-0.77.36.1
libxml2-doc - update to 2.7.6-0.77.36.1
libxml2 - update to 2.7.6-0.77.36.1
libxml2-debuginfo - update to 2.7.6-0.77.36.1
libxml2-debugsource - update to 2.7.6-0.77.36.1
libxml2-python-debuginfo - update to 2.7.6-0.77.36.1
libxml2-python-debugsource - update to 2.7.6-0.77.36.1
libxml2 - update to 2.9.1-6.6.42
libxml2 (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.4, 2.9.10+dfsg-6.3ubuntu0.1, 2.9.10+dfsg-5ubuntu0.20.04.1, 2.9.10+dfsg-5ubuntu0.20.10.2
libxml2-utils (Ubuntu package) - addressed in versions 2.9.4+dfsg1-6.1ubuntu1.4, 2.9.10+dfsg-6.3ubuntu0.1, 2.9.10+dfsg-5ubuntu0.20.04.1, 2.9.10+dfsg-5ubuntu0.20.10.2
mingw-libxml2 - addressed in versions 2.9.10-3.fc31, 2.9.10-3.fc32, 2.9.10-3.fc33, 2.9.10-8.fc32, 2.9.10-8.fc33
libxml2 - addressed in versions 2.9.10-4.fc31, 2.9.10-7.fc32, 2.9.10-7.fc33, 2.9.10-8.fc32, 2.9.10-8.fc33
OpenShift Virtualization - update to 4.8.0
IBM RackSwitch G7028 - update to 7.6.8.0
IBM RackSwitch G8124E - update to 7.11.20.0
IBM RackSwitch G8124 - update to 7.11.20.0
IBM RackSwitch G8052 - update to 7.11.20.0
Brocade Fabric OS - addressed in versions 9.1.1d2, 9.2.0b1, 9.2.1
External References
Related Security Bulletins
- Out-of-bounds read in libxml2
- OpenSUSE Linux update for libxml2
- Out-of-bounds read in libxml2 (Alpine package)
- OpenSUSE Linux update for libxml2
- Arch Linux update for libxml2
- Arch Linux update for libxml2
- Red Hat Enterprise Linux 8 update for libxml2
- Multiple vulnerabilities in cflinuxfs3
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Windows Container Support for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Gentoo update for libxml2
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in Red Hat Web Terminal
- Multiple vulnerabilities in Hitachi Energy RTU500 series CMU
- Multiple vulnerabilities in Hitachi Energy APM Edge
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Oracle HTTP Server
- SUSE update for libxml2
- Ubuntu update for libxml2
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in Oracle HTTP Server
- Amazon Linux AMI update for libxml2
- IBM RackSwitch firmware update for Libxml2
- Multiple vulnerabilities in HPE Brocade Fabric OS
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Fedora 32 update for libxml2
- Fedora 32 update for mingw-libxml2
- Fedora 33 update for mingw-libxml2
- Fedora 31 update for libxml2
- Fedora 31 update for mingw-libxml2
- Fedora 33 update for libxml2
- Fedora 32 update for mingw-libxml2
- Fedora 33 update for mingw-libxml2
- Fedora 32 update for libxml2
- Fedora 33 update for libxml2