Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hm9-844j-jmxp

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Uninitialized read in Nokogiri gem

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

Ссылки

Пакеты

Наименование

nokogiri

rubygems
Затронутые версииВерсия исправления

< 1.10.5

1.10.5

EPSS

Процентиль: 93%
0.06457
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 7 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS3: 5.3
redhat
около 7 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS3: 5.3
nvd
около 7 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

CVSS3: 5.3
debian
около 7 лет назад

In numbers.c in libxslt 1.1.33, an xsl:number with certain format stri ...

CVSS3: 7.5
fstec
около 7 лет назад

Уязвимость функции xsltNumberFormatInsertNumbers библиотеки libxslt, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 93%
0.06457
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-908