Memory Leak Vulnerability in libxml2 Affects Multiple Platforms
CVE-2019-20388

7.5HIGH

Key Information:

Vendor

Xmlsoft

Status
Vendor
CVE Published:
21 January 2020

What is CVE-2019-20388?

The libxml2 library, specifically version 2.9.10, has a vulnerability in the xmlSchemaPreRun function located in xmlschemas.c. This vulnerability can lead to a memory leak during the xmlSchemaValidateStream process, potentially allowing an attacker to exploit this oversight and impact the performance and stability of applications that rely on this library. It is crucial for users and administrators to apply the appropriate updates and patches to mitigate any associated risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.