XML injection (XXE) In nokogiri
Description
Nokogiri vulnerable to libxml XML Entity Expansion The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rubygems | 1.6.6.4 | ||
debian 12 | 2.9.2+really2.9.1+dfsg1-0.1 | ||
debian 13 | 2.9.2+really2.9.1+dfsg1-0.1 | ||
debian 14 | 2.9.2+really2.9.1+dfsg1-0.1 | ||
debian 11 | 2.9.2+really2.9.1+dfsg1-0.1 | ||
rpm rhel7 | 0:2.9.1-6.el7_2.2 | ||
rpm rhel6 | 0:2.7.6-20.el6 | ||
rpm rhel5 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22.