Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-50999

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

A flaw was found in Nokogiri. An integer overflow vulnerability in packaged libxml2 buffer handling functions allows a remote attacker to cause out-of-bounds memory writes. By crafting specially designed, large XML files, an attacker can trigger buffer overflows, leading to potential information disclosure, data modification, or denial of service.

Отчет

This is an Important flaw because it can lead to information disclosure, data modification, or denial of service in Red Hat products that process untrusted, specially crafted multi-gigabyte XML files. The integer overflow in the bundled libxml2 library allows an attacker to cause out-of-bounds memory writes, potentially compromising system integrity or availability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp2/backend-rhel8Not affected
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Not affected
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel9Not affected
Red Hat 3scale API Management Platform 23scale-amp2/toolbox-rhel9Not affected
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel9Not affected
Red Hat Hardened Imageslibxml2Not affected
Red Hat Hardened Imagesswift-langNot affected
Red Hat Satellite 6rubygem-nokogiriNot affected
Red Hat Satellite 6tfm-rubygem-amazing_printNot affected
Red Hat Satellite 6tfm-rubygem-graphqlNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2523554nokogiri: libxml2: Nokogiri: Integer overflow in libxml2 leads to information disclosure, data modification, or denial of service

EPSS

Процентиль: 22%
0.00301
Низкий

7 High

CVSS3

Связанные уязвимости

ubuntu
20 дней назад

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

nvd
20 дней назад

Rejected reason: This CVE ID has been rejected as a duplicate.

CVSS3: 8.6
github
20 дней назад

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.

EPSS

Процентиль: 22%
0.00301
Низкий

7 High

CVSS3