Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 RubyGems

libxslt Type Confusion vulnerability that affects Nokogiri

GHSA-cf46-6xxh-pc75 · CVE-2019-13118

Published · Modified

Description

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

Nokogiri prior to version 1.10.5 used a vulnerable version of libxslt. Nokogiri 1.10.5 updated libxslt to version 1.1.34 to address this and other vulnerabilities in libxslt.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes