CVE-2013-6460
published 2019-11-05CVE-2013-6460: Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.08%
79.6th percentile
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby-nokogiri | — | — |
| nokogiri | nokogiri | >= 1.5.0 < 1.5.11 | 1.5.11 |
| nokogiri | nokogiri | >= 1.5.0 < 1.5.11 | 1.5.11 |
| nokogiri | nokogiri | >= 1.6.0 < 1.6.1 | 1.6.1 |
| nokogiri | nokogiri | >= 1.6.0 < 1.6.1 | 1.6.1 |
| redhat | cloudforms_management_engine | — | — |
| redhat | enterprise_mrg | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | satellite | — | — |
| ruby | nokogiri_gem | — | — |
| ruby | nokogiri_gem | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-nokogiri: DoS while parsing XML documents
vendor_redhat·2013-12-15·CVSS 6.5
CVE-2013-6460 [MEDIUM] rubygem-nokogiri: DoS while parsing XML documents
rubygem-nokogiri: DoS while parsing XML documents
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
Package: mingw-rubygem-nokogiri (CloudForms Management Engine 5) - Not affected
Package: ruby193-rubygem-nokogiri (CloudForms Management Engine 5) - Not affected
Package: rubygem-nokogiri (CloudForms Management Engine 5) - Not affected
Package: rubygem-nokogiri (OpenShift Enterprise 1) - Not affected
Package: rubygem-nokogiri (Red Hat Enterprise MRG 2) - Not affected
Package: rubygem-nokogiri (Red Hat OpenShift Enterprise 2) - Not affected
Package: ruby193-rubygem-nokogiri (Red Hat OpenStack Platform 3) - Not affected
Package: ruby193-rubygem-nokogiri (Red Hat OpenStack Platform 4) - Not affected
Package: ruby193-rubygem-nokogiri (Red Hat Satelli
Debian
CVE-2013-6460: ruby-nokogiri - Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML docu...
vendor_debian·2013·CVSS 6.5
CVE-2013-6460 [MEDIUM] CVE-2013-6460: ruby-nokogiri - Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML docu...
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
Nokogiri vulnerable to DoS while parsing XML documents
osv·2022-05-05
CVE-2013-6460 [MEDIUM] Nokogiri vulnerable to DoS while parsing XML documents
Nokogiri vulnerable to DoS while parsing XML documents
Nokogiri gem has Denial of Service via infinite loop when parsing XML documents
GHSA
Nokogiri vulnerable to DoS while parsing XML documents
ghsa·2022-05-05
CVE-2013-6460 [MEDIUM] CWE-776 Nokogiri vulnerable to DoS while parsing XML documents
Nokogiri vulnerable to DoS while parsing XML documents
Nokogiri gem has Denial of Service via infinite loop when parsing XML documents
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2013/12/27/2http://www.securityfocus.com/bid/64513https://access.redhat.com/security/cve/cve-2013-6460https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6460https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-6460https://exchange.xforce.ibmcloud.com/vulnerabilities/90058https://security-tracker.debian.org/tracker/CVE-2013-6460http://www.openwall.com/lists/oss-security/2013/12/27/2http://www.securityfocus.com/bid/64513https://access.redhat.com/security/cve/cve-2013-6460https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6460https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-6460https://exchange.xforce.ibmcloud.com/vulnerabilities/90058https://security-tracker.debian.org/tracker/CVE-2013-6460
2019-11-05
Published