Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-29181

Опубликовано: 20 мая 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4
CVSS3: 8.2

Описание

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a String by calling #to_s or equivalent.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

1.16.4+dfsg-1build1
esm-apps/bionic

not-affected

code not present
esm-apps/focal

released

1.10.7+dfsg1-2ubuntu0.1~esm2
esm-apps/jammy

released

1.13.1+dfsg-2ubuntu0.1~esm1
esm-apps/noble

not-affected

1.16.2+dfsg-1build1
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
focal

ignored

end of standard support, was needs-triage
impish

ignored

end of life

Показывать по

EPSS

Процентиль: 90%
0.05756
Низкий

6.4 Medium

CVSS2

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
больше 3 лет назад

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent.

CVSS3: 8.2
nvd
больше 3 лет назад

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent.

CVSS3: 8.2
debian
больше 3 лет назад

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri pri ...

CVSS3: 8.2
github
больше 3 лет назад

Nokogiri Improperly Handles Unexpected Data Type

CVSS3: 8.2
fstec
больше 3 лет назад

Уязвимость программной библиотеки Nokogiri интерпретатора Ruby, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

EPSS

Процентиль: 90%
0.05756
Низкий

6.4 Medium

CVSS2

8.2 High

CVSS3