VDB
Sign up
HIGH7.5

GHSA-jc36-42cf-vqwj

Nokogiri affected by zlib's Out-of-bounds Write vulnerability

Quick fix

GHSA-jc36-42cf-vqwj — nokogiri: upgrade to the fixed version with the command below.

bundle update nokogiri

Details

zlib 1.2.11 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/nokogiri
Introduced in: 0Fixed in: 1.13.4
Fixbundle update nokogiri

References