Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6qvp-r6r3-9p7h

Опубликовано: 17 янв. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Nokogiri NULL Pointer Dereference

A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.

Пакеты

Наименование

nokogiri

rubygems
Затронутые версииВерсия исправления

< 1.8.5

1.8.5

EPSS

Процентиль: 95%
0.20012
Средний

7.5 High

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.

CVSS3: 6.5
redhat
больше 7 лет назад

A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.

CVSS3: 6.5
nvd
больше 7 лет назад

A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.

CVSS3: 6.5
debian
больше 7 лет назад

A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPat ...

CVSS3: 4.3
fstec
больше 7 лет назад

Уязвимость функции xpath.c:xmlXPathCompOpEval() библиотеки libxml2, связанная с ошибками разыменования указателя, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 95%
0.20012
Средний

7.5 High

CVSS3

Дефекты

CWE-476