CVE-2019-19956: High severity Siemens SINEMA Remote Connect Server vulnerability
Last updated 25 August 2025
Other sources
libxml2 is vulnerable to a denial of service, caused by a memory leak in xmlParseBalancedChunkMemoryRecover in parser.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-19956.
What is the severity of CVE-2019-19956?
The severity of CVE-2019-19956 is high, with a severity value of 7.5.
How does CVE-2019-19956 affect libxml2?
CVE-2019-19956 affects libxml2 by causing a denial of service due to a memory leak in xmlParseBalancedChunkMemoryRecover in parser.c, which can result in application crashes.
How can CVE-2019-19956 be exploited?
CVE-2019-19956 can be exploited by convincing a victim to open a specially crafted file, allowing a remote attacker to trigger the vulnerability and cause application crashes.
How can I fix CVE-2019-19956?
To fix CVE-2019-19956, update libxml2 to version 2.9.10 or apply the appropriate patch provided by the vendor.