CVE-2022-50998
CVE-2022-50998
8.7
HighPublished:
Last updated:
Source:disclosure@vulncheck.com
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- None
- Integrity (Vulnerable)
- None
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE-2022-40304 (data corruption / double-free from an entity reference cycle when entity content is allocated from a dict) and CVE-2022-40303 (integer overflows when parsing with XML_PARSE_HUGE). Nokogiri 1.13.9 upgrades the packaged libxml2 to v2.10.3 to address these issues. Processing crafted XML input may lead to denial of service or memory corruption. (The advisory also references CVE-2022-2309, a NULL pointer dereference via iterwalk/canonicalize, which maintainers determined does not affect Nokogiri users.)
References
disclosure@vulncheck.com
https://github.com/GNOME/libxml2/commit/644a89e080bced793295f61f18aac8cfad6bece2disclosure@vulncheck.com
https://github.com/GNOME/libxml2/commit/c846986356fc149915a74972bf198abc266bc2c0disclosure@vulncheck.com
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-2qc6-mcvw-92cwdisclosure@vulncheck.com
https://www.vulncheck.com/advisories/nokogiri-before-multiple-vulnerabilities-via-libxml2-2