Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 10, 2023
Description
Published by the National Vulnerability Database
May 14, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 5, 2023
Last updated
Jul 10, 2023
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability.
References