Bugzilla – Bug 877506
VUL-0: rubygem-nokogiri: CVE-2013-2877 and CVE-2014-0191 backport of fixes
Last modified: 2022-02-13 11:07:19 UTC
Via ruby-security list: nokogiri version 1.6.2 has been released. A set of security and bugfix patches have been backported from the libxml2 and libxslt repositories onto the versions of 2.8.0/1.1.28 packaged with Nokogiri, including these notable security fixes: * https://git.gnome.org/browse/libxml2/commit/?id=4629ee02ac649c27f9c0cf98ba017c6b5526070f * CVE-2013-2877 https://git.gnome.org/browse/libxml2/commit/?id=e50ba8164eee06461c73cd8abb9b46aa0be81869 * CVE-2014-0191 https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854df It is recommended that you upgrade from 1.6.x to this version as soon as possible.
This is imho a noop for us. we are not using the intree libxml copy. the fixes mentioned there only apply to the intree copy.
bugbot adjusting priority