Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7hp2-xwpj-95jq

Опубликовано: 17 сент. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of service or RCE from libxml2 and libxslt

Nokogiri is affected by series of vulnerabilities in libxml2 and libxslt, which are libraries Nokogiri depends on. It was discovered that libxml2 and libxslt incorrectly handled certain malformed documents, which can allow malicious users to cause issues ranging from denial of service to remote code execution attacks.

Пакеты

Наименование

nokogiri

rubygems
Затронутые версииВерсия исправления

>= 1.6.0, < 1.6.8

1.6.8

EPSS

Процентиль: 91%
0.06052
Низкий

7.5 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.

redhat
около 10 лет назад

dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.

CVSS3: 7.5
nvd
почти 10 лет назад

dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.

CVSS3: 7.5
debian
почти 10 лет назад

dict.c in libxml2 allows remote attackers to cause a denial of service ...

fstec
почти 10 лет назад

Уязвимость библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 91%
0.06052
Низкий

7.5 High

CVSS3

Дефекты

CWE-125