Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian: DLA-2678-1 Critical Update for Ruby Nokogiri XXE Vulnerability

debian lts
Calendar Grey June 6, 2021
Dist Debian Esm H88
A critical XXE vulnerability in the Ruby library Nokogiri affects versions before 1.12.5, risking sensitive data access; upgrade and review configurations quickly
An XXE vulnerability was found in Nokogiri, a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support

Summary

https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-vr8q-g5c7-m54m

For Debian 9 stretch, this problem has been fixed in version
1.6.8.1-1+deb9u1.

We recommend that you upgrade your ruby-nokogiri packages.

For the detailed security status of ruby-nokogiri please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ruby-nokogiri

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: ruby-nokogiri
Version: 1.6.8.1-1+deb9u1
CVE ID: CVE-2020-26247
Debian Bug: 978967

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here