Out-of-bounds Write in zlib affects Nokogiri
High severity
GitHub Reviewed
Published
Apr 11, 2022
in
sparklemotion/nokogiri
•
Updated Jan 11, 2023
Description
Published to the GitHub Advisory Database
Apr 11, 2022
Reviewed
Apr 11, 2022
Last updated
Jan 11, 2023
Summary
Nokogiri v1.13.4 updates the vendored zlib from 1.2.11 to 1.2.12, which addresses CVE-2018-25032. That CVE is scored as CVSS 7.4 "High" on the NVD record as of 2022-04-05.
Please note that this advisory only applies to the CRuby implementation of Nokogiri
< 1.13.4
, and only if the packaged version ofzlib
is being used. Please see this document for a complete description of which platform gems vendorzlib
. If you've overridden defaults at installation time to use system libraries instead of packaged libraries, you should instead pay attention to your distro'szlib
release announcements.Mitigation
Upgrade to Nokogiri
>= v1.13.4
.Impact
CVE-2018-25032 in zlib
References