UBUNTU-CVE-2022-23476

Source
https://ubuntu.com/security/CVE-2022-23476
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-23476.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-23476
Related
Published
2022-12-08T04:15:00Z
Modified
2024-10-15T14:09:47Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri 1.13.8 and 1.13.9 fail to check the return value from xmlTextReaderExpand in the method Nokogiri::XML::Reader#attribute_hash. This can lead to a null pointer exception when invalid markup is being parsed. For applications using XML::Reader to parse untrusted inputs, this may potentially be a vector for a denial of service attack. Users are advised to upgrade to Nokogiri >= 1.13.10. Users may be able to search their code for calls to either XML::Reader#attributes or XML::Reader#attribute_hash to determine if they are affected.

References

Affected packages

Ubuntu:Pro:14.04:LTS / ruby-nokogiri

Package

Name
ruby-nokogiri
Purl
pkg:deb/ubuntu/ruby-nokogiri?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.5.9-2
1.5.9-3
1.6.0-1
1.6.1+ds-1
1.6.1+ds-1ubuntu0.1~esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / ruby-nokogiri

Package

Name
ruby-nokogiri
Purl
pkg:deb/ubuntu/ruby-nokogiri?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.6.2+ds-2build2
1.6.6.3-1
1.6.7-1
1.6.7.1-1
1.6.7.2-3
1.6.7.2-3build1
1.6.7.2-3ubuntu0.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / ruby-nokogiri

Package

Name
ruby-nokogiri
Purl
pkg:deb/ubuntu/ruby-nokogiri?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.8.0-1
1.8.1-1
1.8.1-1build1
1.8.2-1build1
1.8.2-1ubuntu0.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / ruby-nokogiri

Package

Name
ruby-nokogiri
Purl
pkg:deb/ubuntu/ruby-nokogiri?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.10.3+dfsg1-2
1.10.4+dfsg1-1
1.10.7+dfsg1-1
1.10.7+dfsg1-2
1.10.7+dfsg1-2build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / ruby-nokogiri

Package

Name
ruby-nokogiri
Purl
pkg:deb/ubuntu/ruby-nokogiri?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.11.1+dfsg-2ubuntu1
1.11.7+dfsg-3
1.11.7+dfsg-3build1
1.13.1+dfsg-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / ruby-nokogiri

Package

Name
ruby-nokogiri
Purl
pkg:deb/ubuntu/ruby-nokogiri?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.16.2+dfsg-1build1
1.16.4+dfsg-1
1.16.4+dfsg-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / ruby-nokogiri

Package

Name
ruby-nokogiri
Purl
pkg:deb/ubuntu/ruby-nokogiri?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.14.3+dfsg-2
1.16.0+dfsg-2build1
1.16.2+dfsg-1
1.16.2+dfsg-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}