ADVISORIES
GEM
SEVERITY
CVSS v3.x: 5.5 (Medium)
CVSS v2.0: 4.3 (Medium)
PATCHED VERSIONS
- >= 2.8.2
DESCRIPTION
In the Ox gem 2.8.1 for Ruby, the process crashes with a stack-based buffer over-read in the read_from_str function in sax_buf.c when a crafted input is supplied to sax_parse.