Lucene search

K
osvGoogleOSV:GHSA-7553-JR98-VX47
HistoryFeb 24, 2020 - 7:12 p.m.

libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation

2020-02-2419:12:36
Google
osv.dev
37

0.006 Low

EPSS

Percentile

78.4%

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
The Nokogiri RubyGem has patched its vendored copy of libxml2 in order to prevent this issue from affecting nokogiri.

References