Описание
Nokogiri vulnerable to DoS while parsing XML entities
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-6461
- https://access.redhat.com/security/cve/cve-2013-6461
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6461
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90059
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2013-6461.yml
- https://security-tracker.debian.org/tracker/CVE-2013-6461
- https://web.archive.org/web/20200804224345/https://www.securityfocus.com/bid/64513
- http://www.openwall.com/lists/oss-security/2013/12/27/2
Пакеты
Наименование
nokogiri
rubygems
Затронутые версииВерсия исправления
>= 1.5.0, < 1.5.11
1.5.11
Наименование
nokogiri
rubygems
Затронутые версииВерсия исправления
>= 1.6.0, < 1.6.1
1.6.1
Связанные уязвимости
CVSS3: 6.5
ubuntu
почти 7 лет назад
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
redhat
больше 12 лет назад
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
CVSS3: 6.5
nvd
почти 7 лет назад
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
CVSS3: 6.5
debian
почти 7 лет назад
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by fai ...