CVE-2020-7595: High severity Siemens SINEMA Remote Connect Server vulnerability
GNOME libxml2 is vulnerable to a denial of service, caused by an error in xmlStringLenDecodeEntities in parser.c. An attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
Other sources
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-7595?
The severity of CVE-2020-7595 is high.
What is the affected software version of CVE-2020-7595?
The affected software version of CVE-2020-7595 is libxml2 2.9.10.
How does CVE-2020-7595 affect the software?
CVE-2020-7595 causes an infinite loop in a certain end-of-file situation in libxml2 2.9.10.
What is the recommended remedy for CVE-2020-7595?
The recommended remedy for CVE-2020-7595 is to update to version 2.9.1-6.el7.5 or 2.9.7-8.el8 of libxml2.
Are there any references for CVE-2020-7595?
Yes, there are references available for CVE-2020-7595. Please refer to the following links: https://gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c89076 and https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1799787 and https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1799789.