Lucene search

K
osvGoogleOSV:GHSA-242X-7CM6-4W8J
HistoryMay 24, 2022 - 4:59 p.m.

Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability

2022-05-2416:59:28
Google
osv.dev
10

0.008 Low

EPSS

Percentile

81.7%

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn’t reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

Nokogiri prior to version 1.10.5 contains a vulnerable version of libxslt. Nokogiri version 1.10.5 upgrades the dependency to libxslt 1.1.34, which contains a patch for this issue.

References