Lucene search

K
osvGoogleOSV:GHSA-V4F8-2847-RWM7
HistoryMay 24, 2022 - 7:02 p.m.

Nokogiri Implements libxml2 version vulnerable to use-after-free

2022-05-2419:02:44
Google
osv.dev
12

0.004 Low

EPSS

Percentile

74.0%

There’s a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.

References