CVE-2020-24977: Debian Linux
Medium severity, CVSS 6.5. EPSS: 3% chance of exploitation in the next 30 days.
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
Affected products
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
- Netapp Active Iq Unified Manager: from 7.3; from 9.5
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp Clustered Data Ontap Antivirus Connector: affected versions not specified
- Netapp Hci h410c Firmware: affected versions not specified
- Netapp Inventory Collect Tool: affected versions not specified
- Netapp Manageability Software Development Kit: affected versions not specified
- Netapp Snapdrive: affected versions not specified
- Opensuse Leap: version 15.1 only; version 15.2 only
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment: version 1.10.0 only
- Oracle Enterprise Manager Base Platform: version 13.4.0.0 only; version 13.5.0.0 only
- Oracle Enterprise Manager Ops Center: version 12.4.0.0 only
- Oracle HTTP Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle MySQL Workbench: up to and including 8.0.26
- Oracle PeopleSoft Enterprise PeopleTools: version 8.58 only
- Oracle Real User Experience Insight: version 13.4.1.0 only; version 13.5.1.0 only
- Xmlsoft LIBXML2: version 2.9.10 only
Published 2020-09-04. Last modified 2026-06-17.