CVE-2017-15928

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
5
MEDIUM
Affected
2
PROJECTS

Description

In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.

A fast XML parser and object serializer that uses only standard C lib. Optimized XML (Ox), as the name implies was written to provide speed optimized XML handling. It was designed to be an alternative to Nokogiri and other Ruby XML parsers for generic XML parsing and as an alternative to Marshal for Object serialization.
RubyGemsRubyGems
38M
Ruby Optimized XML Parser
GitHubGitHub
910