VDB

GCVE-110-MAGEIA-2020-77

GCVE-110-MAGEIA-2020-77
Advisory Published
Vulnetix · Advisory published February 9, 2020
A flaw was discovered where the XMLRPC client implementation in Apache XMLRPC, performed deserialization of the server-side exception serialized in the faultCause attribute of XMLRPC error response messages. A malicious or compromised XMLRPC server could possibly use this flaw to execute arbitrary code with the privileges of an application using the Apache XMLRPC client library (CVE-2019-17570).

Affected Products

VendorProductVersionsPlatforms
Mageialibepoxy0 (affected), 1.5.4-1.mga7 (unaffected)
Mageiaxmlrpc3.1.3-73.1.mga7 (unaffected), 0 (affected), 0 (affected), 3.1.3-73.1.mga7 (unaffected)
Mageiax11-server0 (affected), 1.20.7-1.mga7 (unaffected)

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›