CVE-2013-6461: Medium severity Nokogiri Nokogiri vulnerability
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Affected Software
Event History
Frequently Asked Questions
What is CVE-2013-6461?
CVE-2013-6461 is a vulnerability in the Nokogiri gem versions 1.5.x and 1.6.x that can lead to denial of service (DoS) attacks by failing to apply limits while parsing XML entities.
How severe is CVE-2013-6461?
CVE-2013-6461 has a severity rating of 6.5, which is considered medium.
Which software is affected by CVE-2013-6461?
The Nokogiri gem versions 1.5.x and 1.6.x are affected by CVE-2013-6461. Additionally, certain versions of the 'ruby-nokogiri' package in Debian Linux, Redhat Cloudforms Management Engine, Redhat Openstack, Redhat Satellite, Redhat Subscription Asset Manager, and Redhat Enterprise MRG are also affected.
How can I fix CVE-2013-6461?
To fix CVE-2013-6461, make sure you update to version 1.10.0+dfsg1-2 or later of the 'ruby-nokogiri' package in Debian Linux. For other affected software, check with the respective vendors for the latest updates and patches.
Where can I find more information about CVE-2013-6461?
You can find more information about CVE-2013-6461 at the following references: [Openwall](http://www.openwall.com/lists/oss-security/2013/12/27/2), [SecurityFocus](http://www.securityfocus.com/bid/64513), [Red Hat](https://access.redhat.com/security/cve/cve-2013-6461)