CyberICT

CVE-2018-25032

Nokogiri · Published March 25, 2022

CVSS v3.1

HIGH
Patch availableGet patch

Description

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Affected Products

  • Nokogiri < 1.13.4
  • Python < 3.7.14
  • Python < 3.8.14
  • Python < 3.9.13

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H