GHSA-cf46-6xxh-pc75

    Dashboard / Vulnerabilities / GHSA-cf46-6xxh-pc75

    GHSA-cf46-6xxh-pc75

    Published: 24 May 2022Last Modified: 9 Jun 2026

    Summary: libxslt Type Confusion vulnerability that affects Nokogiri

    Details: In `numbers.c` in libxslt 1.1.33, a type holding grouping characters of an `xsl:number` instruction was too narrow and an invalid character/length combination could be passed to `xsltNumberFormatDecimal`, leading to a read of uninitialized stack data. Nokogiri prior to version 1.10.5 used a vulnerable version of libxslt. Nokogiri 1.10.5 updated libxslt to version 1.1.34 to address this and other vulnerabilities in libxslt.

    References: https://nvd.nist.gov/vuln/detail/CVE-2019-13118, https://github.com/sparklemotion/nokogiri/issues/1943, https://github.com/sparklemotion/nokogiri/commit/43a175339b47b8c604508813fc75b83f13cd173e, https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15069, https://seclists.org/bugtraq/2019/Jul/36, https://seclists.org/bugtraq/2019/Jul/37, https://seclists.org/bugtraq/2019/Jul/40, https://seclists.org/bugtraq/2019/Jul/41, https://seclists.org/bugtraq/2019/Jul/42, https://security.netapp.com/advisory/ntap-20190806-0004, https://security.netapp.com/advisory/ntap-20200122-0003, https://support.apple.com/kb/HT210346, https://support.apple.com/kb/HT210348, https://support.apple.com/kb/HT210351, https://support.apple.com/kb/HT210353, https://support.apple.com/kb/HT210356, https://support.apple.com/kb/HT210357, https://support.apple.com/kb/HT210358, https://usn.ubuntu.com/4164-1, https://www.oracle.com/security-alerts/cpujan2020.html, https://github.com/sparklemotion/nokogiri/blob/f7aa3b0b29d6fe5fafe93dacd9b96b6b3d16b7ec/CHANGELOG.md?plain=1#L796, https://github.com/sparklemotion/nokogiri/releases/tag/v1.10.5, https://gitlab.gnome.org/GNOME/libxslt/commit/6ce8de69330783977dd14f6569419489875fb71b, https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E, https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E, https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E, https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E, https://lists.debian.org/debian-lts-announce/2019/07/msg00020.html, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOYJKXPQCUNBMMQJWYXOR6QRUJZHEDRZ, https://lists.fedoraproject.org/archives/list/[email protected]/message/IOYJKXPQCUNBMMQJWYXOR6QRUJZHEDRZ, https://oss-fuzz.com/testcase-detail/5197371471822848, https://seclists.org/bugtraq/2019/Aug/21, https://seclists.org/bugtraq/2019/Aug/22, https://seclists.org/bugtraq/2019/Aug/23, https://seclists.org/bugtraq/2019/Aug/25, https://seclists.org/bugtraq/2019/Jul/35, http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00062.html, http://seclists.org/fulldisclosure/2019/Aug/11, http://seclists.org/fulldisclosure/2019/Aug/13, http://seclists.org/fulldisclosure/2019/Aug/14, http://seclists.org/fulldisclosure/2019/Aug/15, http://seclists.org/fulldisclosure/2019/Jul/22, http://seclists.org/fulldisclosure/2019/Jul/23, http://seclists.org/fulldisclosure/2019/Jul/24, http://seclists.org/fulldisclosure/2019/Jul/26, http://seclists.org/fulldisclosure/2019/Jul/31, http://seclists.org/fulldisclosure/2019/Jul/37, http://seclists.org/fulldisclosure/2019/Jul/38, http://www.openwall.com/lists/oss-security/2019/11/17/2

    Affected packages

    Package

    Name: nokogiri

    Purl: pkg:gem/nokogiri

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.10.5

    Affected versions

    1.0.0
    1.0.1
    1.0.2
    1.0.3
    1.0.4
    1.0.5
    1.0.6
    1.0.7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-cf46-6xxh-pc75 | CVE-DB