CVE-2019-19956: High severity Siemens SINEMA Remote Connect Server vulnerability
Last updated 25 August 2025
Other sources
libxml2 is vulnerable to a denial of service, caused by a memory leak in xmlParseBalancedChunkMemoryRecover in parser.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-36.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-57.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-25.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-36.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-57.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-25.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-openssl-pkcs11to a version that resolves this vulnerability.Fixed in 0:0.4.10-7.jbcs.el7 - Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 0:2.9.1-6.el7.5 - Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 0:2.9.7-8.el8 - Upgrade
Upgrade
Siemens SINEMA Remote Connectto a version that resolves this vulnerability.Fixed in 3.0 - Upgrade
Upgrade
redhat/libxml2to a version that resolves this vulnerability.Fixed in 2.9.10 - Upgrade
Upgrade
debian/libxml2to a version that resolves this vulnerability.Fixed in 2.9.10+dfsg-6.7+deb11u4Fixed in 2.9.10+dfsg-6.7+deb11u10Fixed in 2.9.14+dfsg-1.3~deb12u5Fixed in 2.9.14+dfsg-1.3~deb12u4Fixed in 2.12.7+dfsg+really2.9.14-2.1+deb13u2Fixed in 2.12.7+dfsg+really2.9.14-2.1+deb13u1Fixed in 2.15.3+dfsg-1 - Upgrade
Upgrade
libxml2to a version that resolves this vulnerability.Fixed in 2.9.10
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-19956.
What is the severity of CVE-2019-19956?
The severity of CVE-2019-19956 is high, with a severity value of 7.5.
How does CVE-2019-19956 affect libxml2?
CVE-2019-19956 affects libxml2 by causing a denial of service due to a memory leak in xmlParseBalancedChunkMemoryRecover in parser.c, which can result in application crashes.
How can CVE-2019-19956 be exploited?
CVE-2019-19956 can be exploited by convincing a victim to open a specially crafted file, allowing a remote attacker to trigger the vulnerability and cause application crashes.
How can I fix CVE-2019-19956?
To fix CVE-2019-19956, update libxml2 to version 2.9.10 or apply the appropriate patch provided by the vendor.