GHSA-fr52-4hqw-p27f
Dashboard / Vulnerabilities / GHSA-fr52-4hqw-p27f
Summary: Nokogiri does not forbid namespace nodes in XPointer ranges
Details: xpointer.c in libxml2 before 2.9.5 (as used in nokogiri before 1.7.1 amongst other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and memory corruption) via a crafted XML document.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-4658, https://git.gnome.org/browse/libxml2/commit/?id=c1d1f7121194036608bf555f08d3062a36fd344b, https://security.gentoo.org/glsa/201701-37, https://support.apple.com/HT207141, https://support.apple.com/HT207142, https://support.apple.com/HT207143, https://support.apple.com/HT207170, http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html, http://lists.apple.com/archives/security-announce/2016/Sep/msg00008.html, http://lists.apple.com/archives/security-announce/2016/Sep/msg00010.html, http://lists.apple.com/archives/security-announce/2016/Sep/msg00011.html
Affected packages
Package
Name: nokogiri
Purl: pkg:gem/nokogiri
Affected ranges
Type: ECOSYSTEM
Events:
