--- gem: ox cve: 2017-16229 url: https://github.com/ohler55/ox/issues/195 date: 2017-10-29 title: ox ruby gem stack overflow in sax_parse description: | In the Ox gem 2.8.1 for Ruby, the process crashes with a stack-based buffer over-read in the read_from_str function in sax_buf.c when a crafted input is supplied to sax_parse. cvss_v3: 5.5 cvss_v2: 4.3 patched_versions: - ">= 2.8.2"