Input validation error in Nokogiri - CVE-2022-29181

 

Input validation error in Nokogiri - CVE-2022-29181

Published: November 24, 2022


Vulnerability identifier: #VU69583
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29181
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input passed into the XML and HTML4 SAX parsers. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Nokogiri
Amazon Linux AMI
Gentoo Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Fedora
SUSE OpenStack Cloud Crowbar
macOS
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
Ubuntu
Log Analysis
IBM Watson Machine Learning Accelerator
rubygem-nokogiri
ruby2.1-rubygem-nokogiri-debuginfo
rubygem-nokogiri-debugsource
ruby2.1-rubygem-nokogiri
ruby2.5-rubygem-nokogiri
ruby2.5-rubygem-nokogiri-debuginfo
ruby2.5-rubygem-nokogiri-doc
ruby2.5-rubygem-nokogiri-testsuite
ruby-nokogiri (Ubuntu package)
dev-ruby/nokogiri

How to mitigate CVE-2022-29181

Install updates from vendor's website.

Nokogiri - update to 1.13.6
Log Analysis - update to 1.3.8
macOS - update to 13.1 22C65
rubygem-nokogiri - addressed in versions 1.6.1-1.el7.2, 1.11.7-3.fc34, 1.13.1-3.fc35, 1.13.6-1.el9, 1.13.6-1.fc36
rubygem-nokogiri - update to 1.6.1-1.23
ruby2.1-rubygem-nokogiri-debuginfo - update to 1.6.1-5.6.1
rubygem-nokogiri-debugsource - addressed in versions 1.6.1-5.6.1, 1.8.5-150000.3.9.1, 1.8.5-150400.14.3.1
ruby2.1-rubygem-nokogiri - update to 1.6.1-5.6.1
ruby2.5-rubygem-nokogiri - addressed in versions 1.8.5-150000.3.9.1, 1.8.5-150400.14.3.1
ruby2.5-rubygem-nokogiri-debuginfo - addressed in versions 1.8.5-150000.3.9.1, 1.8.5-150400.14.3.1
ruby2.5-rubygem-nokogiri-doc - addressed in versions 1.8.5-150000.3.9.1, 1.8.5-150400.14.3.1
ruby2.5-rubygem-nokogiri-testsuite - addressed in versions 1.8.5-150000.3.9.1, 1.8.5-150400.14.3.1
ruby-nokogiri (Ubuntu package) - addressed in versions 1.10.7+dfsg1-2ubuntu0.1~esm2, 1.13.1+dfsg-2ubuntu0.1~esm1
dev-ruby/nokogiri - update to 1.13.6

External References

Related Security Bulletins