Lucene search

K
osvGoogleOSV:GHSA-882P-JQGM-F45G
HistoryApr 13, 2018 - 4:17 p.m.

Uncontrolled resource consumption in nokogiri

2018-04-1316:17:46
Google
osv.dev
20

EPSS

0.017

Percentile

87.9%

The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.