Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fr52-4hqw-p27f

Опубликовано: 21 авг. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Nokogiri does not forbid namespace nodes in XPointer ranges

xpointer.c in libxml2 before 2.9.5 (as used in nokogiri before 1.7.1 amongst other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

Пакеты

Наименование

nokogiri

rubygems
Затронутые версииВерсия исправления

< 1.7.1

1.7.1

EPSS

Процентиль: 95%
0.19344
Средний

9.8 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

CVSS3: 5.3
redhat
больше 9 лет назад

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

CVSS3: 9.8
nvd
больше 9 лет назад

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

CVSS3: 9.8
debian
больше 9 лет назад

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS ...

suse-cvrf
больше 9 лет назад

Security update for libxml2

EPSS

Процентиль: 95%
0.19344
Средний

9.8 Critical

CVSS3

Дефекты

CWE-119