USN-4175-1: Nokogiri vulnerability
Published Nov 5, 2019
·Updated
It was discovered that Nokogiri incorrectly handled inputs. A remote attacker could possibly use this issue to execute arbitrary OS commands.
Affected Software
1 affected component
gem/nokogiri
Event History
Feb 23, 2026
Advisory Published
via Ubuntu·04:28 PM
Data Sourced
via Ubuntu·04:28 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Nokogiri vulnerability?
The vulnerability ID for this Nokogiri vulnerability is CVE-2019-5477.
2
What is the severity of the Nokogiri vulnerability?
The severity of the Nokogiri vulnerability is not specified in the provided information.
3
How can a remote attacker exploit the Nokogiri vulnerability?
A remote attacker can exploit the Nokogiri vulnerability by using it to execute arbitrary OS commands.
4
Which versions of Ruby Nokogiri are affected by this vulnerability?
The versions of Ruby Nokogiri affected by this vulnerability are 1.10.3+dfsg1-2ubuntu0.1, 1.10.0+dfsg1-2ubuntu0.1, 1.8.2-1ubuntu0.1, and 1.6.7.2-3ubuntu0.1.
5
How can I fix the Nokogiri vulnerability?
To fix the Nokogiri vulnerability, update the package 'ruby-nokogiri' to the specified remedial versions provided in the references.