Launch Week Day 1: Announcing Security Design Review
UNKNOWN RubyGems

Nokogiri subject to DoS via libxml2 vulnerability

GHSA-xjqg-9jvg-fgx2 · CVE-2015-5312

Published · Modified

Description

The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 (as used in nokogiri before 1.6.7.1) does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.

Ready to move

Start Securing

Free, no credit card | First findings in minutes