CVE-2020-24977: Debian Linux

Medium severity, CVSS 6.5. EPSS: 3% chance of exploitation in the next 30 days.

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp Clustered Data Ontap: affected versions not specified
  • Netapp Clustered Data Ontap Antivirus Connector: affected versions not specified
  • Netapp Hci h410c Firmware: affected versions not specified
  • Netapp Inventory Collect Tool: affected versions not specified
  • Netapp Manageability Software Development Kit: affected versions not specified
  • Netapp Snapdrive: affected versions not specified
  • Opensuse Leap: version 15.1 only; version 15.2 only
  • Oracle Communications Cloud Native Core Network Function Cloud Native Environment: version 1.10.0 only
  • Oracle Enterprise Manager Base Platform: version 13.4.0.0 only; version 13.5.0.0 only
  • Oracle Enterprise Manager Ops Center: version 12.4.0.0 only
  • Oracle HTTP Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle MySQL Workbench: up to and including 8.0.26
  • Oracle PeopleSoft Enterprise PeopleTools: version 8.58 only
  • Oracle Real User Experience Insight: version 13.4.1.0 only; version 13.5.1.0 only
  • Xmlsoft LIBXML2: version 2.9.10 only

Published 2020-09-04. Last modified 2026-06-17.