Date: Tue, 30 Dec 2014 07:01:20 +0000 From: David Jorm <djorm@...p.iixpeering.net> To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com> Subject: 2012 CVE request: XXE in nokogiri ruby gem Hi All An XXE issue was reported and fixed in nokogiri, but as far as I can see no CVE ID was ever assigned. It appears a lot of people haven't updated their dependencies as a result, so a CVE ID would be helpful. For details, see: https://github.com/sparklemotion/nokogiri/issues/693#issuecomment-68334768 Thanks -- David Jorm / IIX Product Security
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.