Uncontrolled resource consumption in nokogiri
Moderate severity
GitHub Reviewed
Published
Apr 13, 2018
to the GitHub Advisory Database
•
Updated May 4, 2023
Description
Published by the National Vulnerability Database
Apr 8, 2018
Published to the GitHub Advisory Database
Apr 13, 2018
Reviewed
Jun 16, 2020
Last updated
May 4, 2023
The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory consumption) via a crafted LZMA file, because the decoder functionality does not restrict memory usage to what is required for a legitimate file.
References