Lucene search

K
osvGoogleOSV:GHSA-6QVP-R6R3-9P7H
HistoryJan 17, 2019 - 2:05 p.m.

Nokogiri NULL Pointer Dereference

2019-01-1714:05:03
Google
osv.dev
23

0.03 Low

EPSS

Percentile

90.9%

A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.