ALT-PU-2024-2138-1
Package gem-nokogiri updated to version 1.16.2-alt1 for branch sisyphus_loongarch64.
Closed vulnerabilities
Published: 2024-02-04
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2024-25062
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References: