Sha256: 228bc2655dba3d56fec3d73c97ac7804bdd48dd9380fa5e42a963433bc2b9604

Contents?: true

Size: 520 Bytes

Versions: 1

Compression:

Stored size: 520 Bytes

Contents

---
gem: nokogiri
cve: 2020-7595
url: https://github.com/sparklemotion/nokogiri/issues/1992
date: 2020-02-12
title: libxml2 2.9.10 has an infinite loop in a certain end-of-file situation
description: |-

  Nokogiri has backported the patch for CVE-2020-7595 into its vendored version
  of libxml2, and released this as v1.10.8

  CVE-2020-7595 has not yet been addressed in an upstream libxml2 release, and
  so Nokogiri versions <= v1.10.7 are vulnerable.

patched_versions:
  - ">= 1.10.8"

cvss_v2: 5.0
cvss_v3: 7.5

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/nokogiri/CVE-2020-7595.yml