|
| 1 | +--- |
| 2 | +gem: nokogiri |
| 3 | +cve: 2019-11068 |
| 4 | +date: 2019-04-22 |
| 5 | +url: https://github.com/sparklemotion/nokogiri/issues/1892 |
| 6 | +title: Nokogiri gem, via libxslt, is affected by improper access control vulnerability |
| 7 | +description: | |
| 8 | + Nokogiri v1.10.3 has been released. |
| 9 | +
|
| 10 | + This is a security release. It addresses a CVE in upstream libxslt rated as |
| 11 | + "Priority: medium" by Canonical, and "NVD Severity: high" by Debian. More |
| 12 | + details are available below. |
| 13 | +
|
| 14 | + If you're using your distro's system libraries, rather than Nokogiri's |
| 15 | + vendored libraries, there's no security need to upgrade at this time, though |
| 16 | + you may want to check with your distro whether they've patched this |
| 17 | + (Canonical has patched Ubuntu packages). Note that this patch is not yet (as |
| 18 | + of 2019-04-22) in an upstream release of libxslt. |
| 19 | +
|
| 20 | + Full details about the security update are available in Github Issue |
| 21 | + [#1892] https://github.com/sparklemotion/nokogiri/issues/1892. |
| 22 | +
|
| 23 | + --- |
| 24 | +
|
| 25 | + CVE-2019-11068 |
| 26 | +
|
| 27 | + Permalinks are: |
| 28 | + - Canonical: https://people.canonical.com/~ubuntu-security/cve/CVE-2019-11068 |
| 29 | + - Debian: https://security-tracker.debian.org/tracker/CVE-2019-11068 |
| 30 | +
|
| 31 | + Description: |
| 32 | +
|
| 33 | + > libxslt through 1.1.33 allows bypass of a protection mechanism |
| 34 | + > because callers of xsltCheckRead and xsltCheckWrite permit access |
| 35 | + > even upon receiving a -1 error code. xsltCheckRead can return -1 for |
| 36 | + > a crafted URL that is not actually invalid and is subsequently |
| 37 | + > loaded. |
| 38 | +
|
| 39 | + Canonical rates this as "Priority: Medium". |
| 40 | +
|
| 41 | + Debian rates this as "NVD Severity: High (attack range: remote)". |
| 42 | +
|
| 43 | +patched_versions: |
| 44 | + - ">= 1.10.3" |
| 45 | + |
| 46 | +related: |
| 47 | + url: |
| 48 | + - https://groups.google.com/forum/#!msg/ruby-security-ann/_y80o1zZlOs/k4SDX6hoAAAJ |
| 49 | + - https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6 |
0 commit comments