Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6178
HistoryApr 24, 2018 - 2:43 a.m.

Copy-Paste Vulnerability Through LibXML2

2018-04-2402:43:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.017 Low

EPSS

Percentile

87.9%

Nokogiri is vulnerable to attacks through a copied version of LibXML2 within the codebase. LibXML2 before 2.9.5 is vulnerable to CVE-2017-18258 - the LibXML2 decoder does not limit memory usage for what is required when decoding LZMA files.