Sha256: f21e968fba014d44a7025ffa1b963b027708ea683810639825ed71c59418601b

Contents?: true

Size: 738 Bytes

Versions: 3

Compression:

Stored size: 738 Bytes

Contents

---
gem: nokogiri
cve: 2017-16932
url: https://github.com/sparklemotion/nokogiri/issues/1714
title: Nokogiri gem, via libxml, is affected by DoS vulnerabilities
date: 2018-01-29
description: |
  The version of libxml2 packaged with Nokogiri contains a
  vulnerability. Nokogiri has mitigated these issue by upgrading to
  libxml 2.9.5.

  Wei Lei discovered that libxml2 incorrecty handled certain parameter
  entities. An attacker could use this issue with specially constructed XML
  data to cause libxml2 to consume resources, leading to a denial of service.

patched_versions:
  - ">= 1.8.1"
related:
  url:
    - https://usn.ubuntu.com/usn/usn-3504-1/
    - https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-16932.html

Version data entries

3 entries across 3 versions & 2 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/nokogiri/CVE-2017-16932.yml
bundler-budit-0.6.2 data/ruby-advisory-db/gems/nokogiri/CVE-2017-16932.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/nokogiri/CVE-2017-16932.yml