VDB
KO
MEDIUM 6.5

GHSA-882p-jqgm-f45g

Uncontrolled resource consumption in nokogiri

Details

The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / nokogiri
Introduced in: 0 Fixed in: 1.8.2
Fix bundle update nokogiri

References