Lack of data validation - Type confusion In nokogiri
Description
libxslt Type Confusion vulnerability that affects Nokogiri
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
Nokogiri prior to version 1.10.5 used a vulnerable version of libxslt. Nokogiri 1.10.5 updated libxslt to version 1.1.34 to address this and other vulnerabilities in libxslt.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.9 | 1.1.33-r3 | ||
alpine v3.12 | 1.1.34-r0 | ||
alpine v3.17 | 1.1.34-r0 | ||
alpine v3.18 | 1.1.34-r0 | ||
alpine v3.21 | 1.1.34-r0 | ||
alpine v3.11 | 1.1.34-r0 | ||
alpine v3.19 | 1.1.34-r0 | ||
alpine v3.20 | 1.1.34-r0 | ||
alpine v3.10 | 1.1.33-r3 | ||
alpine v3.13 | 1.1.34-r0 |
1-10 of 25
10
Aliases
References