PublicDateAtUSN: 2020-09-04 00:15:00 UTC Candidate: CVE-2020-24977 PublicDate: 2020-09-04 00:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24977 https://ubuntu.com/security/notices/USN-4991-1 Description: GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e. Ubuntu-Description: Notes: mdeslaur> only affects xmllint mdeslaur> contrary to description, not fixed in 8e7c20a1 Mitigation: Bugs: https://bugs.launchpad.net/bugs/1895839 https://gitlab.gnome.org/GNOME/libxml2/-/issues/178 Priority: low Discovered-by: Assigned-to: avital CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L [6.5 MEDIUM] Patches_libxml2: upstream: https://gitlab.gnome.org/GNOME/libxml2/-/commit/50f06b3efb638efb0abd95dc62dca05ae67882c2 upstream_libxml2: released (2.9.10+dfsg-6.2) precise/esm_libxml2: ignored (end of ESM support, was needed) trusty_libxml2: ignored (out of standard support) trusty/esm_libxml2: released (2.9.1+dfsg1-3ubuntu4.13+esm2) xenial_libxml2: ignored (end of standard support, was needed) esm-infra/xenial_libxml2: released (2.9.3+dfsg1-1ubuntu0.7+esm1) bionic_libxml2: released (2.9.4+dfsg1-6.1ubuntu1.4) focal_libxml2: released (2.9.10+dfsg-5ubuntu0.20.04.1) groovy_libxml2: released (2.9.10+dfsg-5ubuntu0.20.10.2) hirsute_libxml2: not-affected (2.9.10+dfsg-6.3build2) impish_libxml2: not-affected (2.9.10+dfsg-6.3build2) jammy_libxml2: not-affected (2.9.10+dfsg-6.3build2) devel_libxml2: not-affected (2.9.10+dfsg-6.3build2)