Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fr52-4hqw-p27f

Опубликовано: 21 авг. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Nokogiri does not forbid namespace nodes in XPointer ranges

xpointer.c in libxml2 before 2.9.5 (as used in nokogiri before 1.7.1 amongst other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

Пакеты

Наименование

nokogiri

rubygems
Затронутые версииВерсия исправления

< 1.7.1

1.7.1

EPSS

Процентиль: 94%
0.08628
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 10 лет назад

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

CVSS3: 5.3
redhat
почти 10 лет назад

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

CVSS3: 9.8
nvd
почти 10 лет назад

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.

CVSS3: 9.8
debian
почти 10 лет назад

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS ...

suse-cvrf
почти 10 лет назад

Security update for libxml2

EPSS

Процентиль: 94%
0.08628
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119