Nokogiri implementation of libxslt vulnerable to heap corruption
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 10, 2023
Description
Published by the National Vulnerability Database
Dec 11, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 7, 2023
Last updated
Jul 10, 2023
Type confusion in
xsltNumberFormatGetMultipleLevel
prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.Nokogiri prior to version 1.10.5 contains a vulnerable version of libxslt. Nokogiri version 1.10.5 upgrades the dependency to libxslt 1.1.34, which contains a patch for this issue.
References