CVE-2013-6461
published 2019-11-05CVE-2013-6461: Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.19%
80.6th percentile
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby-nokogiri | — | — |
| nokogiri | nokogiri | >= 1.5.0 < 1.5.11 | 1.5.11 |
| nokogiri | nokogiri | >= 1.5.0 < 1.5.11 | 1.5.11 |
| nokogiri | nokogiri | >= 1.6.0 < 1.6.1 | 1.6.1 |
| nokogiri | nokogiri | >= 1.6.0 < 1.6.1 | 1.6.1 |
| redhat | cloudforms_management_engine | — | — |
| redhat | enterprise_mrg | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | satellite | — | — |
| ruby | nokogiri_gem | — | — |
| ruby | nokogiri_gem | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Nokogiri vulnerable to DoS while parsing XML entities
ghsa·2022-05-05
CVE-2013-6461 [MEDIUM] CWE-776 Nokogiri vulnerable to DoS while parsing XML entities
Nokogiri vulnerable to DoS while parsing XML entities
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
OSV
Nokogiri vulnerable to DoS while parsing XML entities
osv·2022-05-05
CVE-2013-6461 [MEDIUM] Nokogiri vulnerable to DoS while parsing XML entities
Nokogiri vulnerable to DoS while parsing XML entities
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Red Hat
rubygem-nokogiri: DoS while parsing XML entities
vendor_redhat·2013-12-15·CVSS 6.5
CVE-2013-6461 [MEDIUM] rubygem-nokogiri: DoS while parsing XML entities
rubygem-nokogiri: DoS while parsing XML entities
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Package: mingw-rubygem-nokogiri (CloudForms Management Engine 5) - Not affected
Package: ruby193-rubygem-nokogiri (CloudForms Management Engine 5) - Not affected
Package: rubygem-nokogiri (CloudForms Management Engine 5) - Not affected
Package: rubygem-nokogiri (OpenShift Enterprise 1) - Not affected
Package: rubygem-nokogiri (Red Hat Enterprise MRG 2) - Not affected
Package: rubygem-nokogiri (Red Hat OpenShift Enterprise 2) - Not affected
Package: ruby193-rubygem-nokogiri (Red Hat OpenStack Platform 3) - Not affected
Package: ruby193-rubygem-nokogiri (Red Hat OpenStack Platform 4) - Not affected
Package: ruby193-rubygem-nokogiri (Red Hat Sat
Debian
CVE-2013-6461: ruby-nokogiri - Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to ap...
vendor_debian·2013·CVSS 6.5
CVE-2013-6461 [MEDIUM] CVE-2013-6461: ruby-nokogiri - Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to ap...
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2013/12/27/2http://www.securityfocus.com/bid/64513https://access.redhat.com/security/cve/cve-2013-6461https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6461https://exchange.xforce.ibmcloud.com/vulnerabilities/90059https://security-tracker.debian.org/tracker/CVE-2013-6461http://www.openwall.com/lists/oss-security/2013/12/27/2http://www.securityfocus.com/bid/64513https://access.redhat.com/security/cve/cve-2013-6461https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6461https://exchange.xforce.ibmcloud.com/vulnerabilities/90059https://security-tracker.debian.org/tracker/CVE-2013-6461
2019-11-05
Published