CVE-2019-20388: High severity IBM Security Guardium vulnerability
A memory leak was found in the xmlSchemaValidateStream function of libxml2. Applications that use this library may be vulnerable to memory not being freed leading to a denial of service. System availability is the highest threat from this vulnerability.
Other sources
GNOME libxml2 could allow a remote attacker to obtain sensitive information, caused by a xmlSchemaValidateStream memory leak in xmlSchemaPreRun in xmlschemas.c. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to obtain sensitive information.
— IBM
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-20388.
What is the title of this vulnerability?
The title of this vulnerability is 'xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.'
What is the severity of CVE-2019-20388?
The severity of CVE-2019-20388 is high, with a severity value of 7.
What is the description of CVE-2019-20388?
The vulnerability allows for a memory leak in the xmlSchemaValidateStream function of libxml2, which can lead to a denial of service and impact system availability.
What software is affected by CVE-2019-20388?
The affected software includes 'jbcs-httpd24-curl', 'jbcs-httpd24-httpd', 'jbcs-httpd24-nghttp2', 'jbcs-httpd24-openssl-pkcs11', 'libxml2', and their specific versions on different platforms.
Where can I find more information about CVE-2019-20388?
More information about CVE-2019-20388 can be found on the following references: [link1], [link2], [link3].
What is the Common Weakness Enumeration (CWE) ID of CVE-2019-20388?
The Common Weakness Enumeration (CWE) ID of CVE-2019-20388 is CWE-401.