Skip to content

Commit 7045b4f

Browse files
committed
Add CVE-2019-11068 for nokogiri
1 parent 0af08a0 commit 7045b4f

File tree

1 file changed

+49
-0
lines changed

1 file changed

+49
-0
lines changed

gems/nokogiri/CVE-2019-11068.yml

Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
---
2+
gem: nokogiri
3+
cve: 2019-11068
4+
date: 2019-04-22
5+
url: https://github.com/sparklemotion/nokogiri/issues/1892
6+
title: Nokogiri gem, via libxslt, is affected by improper access control vulnerability
7+
description: |
8+
Nokogiri v1.10.3 has been released.
9+
10+
This is a security release. It addresses a CVE in upstream libxslt rated as
11+
"Priority: medium" by Canonical, and "NVD Severity: high" by Debian. More
12+
details are available below.
13+
14+
If you're using your distro's system libraries, rather than Nokogiri's
15+
vendored libraries, there's no security need to upgrade at this time, though
16+
you may want to check with your distro whether they've patched this
17+
(Canonical has patched Ubuntu packages). Note that this patch is not yet (as
18+
of 2019-04-22) in an upstream release of libxslt.
19+
20+
Full details about the security update are available in Github Issue
21+
[#1892] https://github.com/sparklemotion/nokogiri/issues/1892.
22+
23+
---
24+
25+
CVE-2019-11068
26+
27+
Permalinks are:
28+
- Canonical: https://people.canonical.com/~ubuntu-security/cve/CVE-2019-11068
29+
- Debian: https://security-tracker.debian.org/tracker/CVE-2019-11068
30+
31+
Description:
32+
33+
> libxslt through 1.1.33 allows bypass of a protection mechanism
34+
> because callers of xsltCheckRead and xsltCheckWrite permit access
35+
> even upon receiving a -1 error code. xsltCheckRead can return -1 for
36+
> a crafted URL that is not actually invalid and is subsequently
37+
> loaded.
38+
39+
Canonical rates this as "Priority: Medium".
40+
41+
Debian rates this as "NVD Severity: High (attack range: remote)".
42+
43+
patched_versions:
44+
- ">= 1.10.3"
45+
46+
related:
47+
url:
48+
- https://groups.google.com/forum/#!msg/ruby-security-ann/_y80o1zZlOs/k4SDX6hoAAAJ
49+
- https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6

0 commit comments

Comments
 (0)