VDB
KO
HIGH 7.5

GHSA-7553-jr98-vx47

libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation

Details

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. The Nokogiri RubyGem has patched its vendored copy of libxml2 in order to prevent this issue from affecting nokogiri.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / nokogiri
Introduced in: 0 Fixed in: 1.10.8
Fix bundle update nokogiri

References