Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2013-6460 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6460 | issue tracking patch exploit third party advisory |
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-6460 | issue tracking third party advisory |
https://access.redhat.com/security/cve/cve-2013-6460 | third party advisory |
http://www.openwall.com/lists/oss-security/2013/12/27/2 | third party advisory mailing list |
http://www.securityfocus.com/bid/64513 | vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/90058 | vdb entry third party advisory |