The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Vulnerability of Nokogiri: external XML entity injection via Nokogiri-XML-Schema

Synthesis of the vulnerability 

An attacker can transmit malicious XML data via Nokogiri::XML::Schema() to Nokogiri, in order to read a file, scan sites, or trigger a denial of service.
Impacted products: Debian, openSUSE Leap, SLES.
Severity of this bulletin: 2/4.
Creation date: 01/02/2021.
Références of this threat: CVE-2020-26247, DLA-2678-1, openSUSE-SU-2021:0237-1, SUSE-SU-2021:0251-1, VIGILANCE-VUL-34449.

Description of the vulnerability 

An attacker can transmit malicious XML data via Nokogiri::XML::Schema() to Nokogiri, in order to read a file, scan sites, or trigger a denial of service.
Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

This weakness announce impacts software or systems such as Debian, openSUSE Leap, SLES.

Our Vigil@nce team determined that the severity of this vulnerability alert is medium.

The trust level is of type confirmed by the editor, with an origin of document.

An attacker with a expert ability can exploit this computer threat announce.

Solutions for this threat 

Debian 9: new ruby-nokogiri packages.
New packages are available:
  Debian 9: ruby-nokogiri 1.6.8.1-1+deb9u1

openSUSE Leap 15.2: new rubygem-nokogiri packages.
New packages are available:
  openSUSE Leap 15.2: ruby2.5-rubygem-nokogiri 1.8.5-lp152.4.3.1

SUSE LE 15 RTM-SP2: new rubygem-nokogiri packages.
New packages are available:
  SUSE LE 15 RTM: ruby2.5-rubygem-nokogiri 1.8.5-3.6.1
  SUSE LE 15 SP1: ruby2.5-rubygem-nokogiri 1.8.5-3.6.1
  SUSE LE 15 SP2: ruby2.5-rubygem-nokogiri 1.8.5-3.6.1
Full bulletin, software filtering, emails, fixes, ... (Request your free trial)

Computer vulnerabilities tracking service 

Vigil@nce provides a system vulnerability database. Each administrator can customize the list of products for which he wants to receive vulnerability alerts.