Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2013-6461 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6461 | third party advisory issue tracking exploit |
https://access.redhat.com/security/cve/cve-2013-6461 | third party advisory |
http://www.openwall.com/lists/oss-security/2013/12/27/2 | third party advisory mailing list |
http://www.securityfocus.com/bid/64513 | third party advisory vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/90059 | third party advisory vdb entry |