CVE-2017-5029: Upstream libxslt vulnerabilities
(updated )
The xsltAddTextString
function in transform.c
in libxslt, as used by nokogiri, lacks a check for integer overflow during a size calculation, which allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page.
References
Detect and mitigate CVE-2017-5029 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →