CVE-2015-1819

medium
Published 2015-04-14 · Modified 2024-11-29
CVSS v3
CVSS v2
5.0
VIR risk
5.0

Description

Nokogiri vulnerable to libxml XML Entity Expansion

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-1819

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://git.gnome.org/browse/libxml2/commit/?id=213f1fe0d76d30eaed6e5853057defc43e6df2c9

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.9.2+really2.9.1+dfsg1-0.1
debian debianbullseyefixed2.9.2+really2.9.1+dfsg1-0.1
debian debianforkyfixed2.9.2+really2.9.1+dfsg1-0.1
debian debiansidfixed2.9.2+really2.9.1+dfsg1-0.1
debian debiantrixiefixed2.9.2+really2.9.1+dfsg1-0.1
redhat rhelaffected
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu15.04affected
debian debian7.0affected
debian debian8.0affected
suse suse13.1affected
suse suse13.2affected
macos macosaffected
fedora fedora22affected
fedora fedora23affected

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsnokogiri<~> 1.6.6.4~> 1.6.6.4
ruby RubyGemsnokogiri>=1.6.6.0,<1.6.6.41.6.6.4

Application impact

VendorProductVersionsFixed
xmlsoftlibxml

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.