HIGH7.5
GHSA-jc36-42cf-vqwj
Nokogiri affected by zlib's Out-of-bounds Write vulnerability
Quick fix
GHSA-jc36-42cf-vqwj — nokogiri: upgrade to the fixed version with the command below.
bundle update nokogiriDetails
zlib 1.2.11 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v6gp-9mmm-c6p5[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2018-25032[ADVISORY]
- https://github.com/madler/zlib/issues/605[WEB]
- https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531[WEB]
- https://www.oracle.com/security-alerts/cpujul2022.html[WEB]
- https://www.openwall.com/lists/oss-security/2022/03/28/3[WEB]
- https://www.openwall.com/lists/oss-security/2022/03/28/1[WEB]
- https://www.openwall.com/lists/oss-security/2022/03/24/1[WEB]
- https://www.debian.org/security/2022/dsa-5111[WEB]
- https://support.apple.com/kb/HT213257[WEB]
- https://support.apple.com/kb/HT213256[WEB]
- https://support.apple.com/kb/HT213255[WEB]
- https://security.netapp.com/advisory/ntap-20220729-0004[WEB]
- https://security.netapp.com/advisory/ntap-20220526-0009[WEB]
- https://security.gentoo.org/glsa/202210-42[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF[WEB]
- https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html[WEB]
- https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html[WEB]
- https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2018-25032.yml[WEB]
- https://github.com/madler/zlib/compare/v1.2.11...v1.2.12[WEB]
- https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf[WEB]
- http://seclists.org/fulldisclosure/2022/May/33[WEB]
- http://seclists.org/fulldisclosure/2022/May/35[WEB]
- http://seclists.org/fulldisclosure/2022/May/38[WEB]
- http://www.openwall.com/lists/oss-security/2022/03/25/2[WEB]
- http://www.openwall.com/lists/oss-security/2022/03/26/1[WEB]