CVE-2018-14404
HIGH7.5EPSS 20.0%Nokogiri NULL Pointer Dereference
發布日:2019/1/17修改日:2026/4/28
描述
A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.
受影響套件(3)
- Alpine/libxml2from 0, < 2.9.8-r1
- Debian/libxml2from 0, < 2.9.10+dfsg-2
- RubyGems/nokogirifrom 0, < 1.8.5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
參考連結(14)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2018-14404
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2018-14404
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2018-14404
- WEBhttps://access.redhat.com/errata/RHSA-2019:1543
- WEBhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=901817
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=1595985
- WEBhttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2018-14404.yml
- WEBhttps://github.com/sparklemotion/nokogiri/issues/1785
- WEBhttps://gitlab.gnome.org/GNOME/libxml2/issues/10
- WEBhttps://lists.debian.org/debian-lts-announce/2018/09/msg00035.html
- WEBhttps://lists.debian.org/debian-lts-announce/2020/09/msg00009.html
- WEBhttps://security.netapp.com/advisory/ntap-20190719-0002
- WEBhttps://usn.ubuntu.com/3739-1
- WEBhttps://usn.ubuntu.com/3739-2