Medium severity6.5NVD Advisory· Published Nov 5, 2019· Updated Jun 17, 2026
CVE-2013-6461
CVE-2013-6461
Description
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nokogiriRubyGems | >= 1.5.0, < 1.5.11 | 1.5.11 |
nokogiriRubyGems | >= 1.6.0, < 1.6.1 | 1.6.1 |
Affected products
12- cpe:2.3:a:redhat:cloudforms_management_engine:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:subscription_asset_manager:-:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*
- Ruby/Nokogiri gemv5Range: 1.5.x
Patches
Vulnerability mechanics
References
10- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2013/12/27/2nvdMailing ListThird Party AdvisoryWEB
- www.securityfocus.com/bid/64513nvdThird Party AdvisoryVDB Entry
- access.redhat.com/security/cve/cve-2013-6461nvdThird Party AdvisoryWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/90059nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-jmhh-w7xp-wg39ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-6461ghsaADVISORY
- security-tracker.debian.org/tracker/CVE-2013-6461nvdThird Party AdvisoryWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2013-6461.ymlghsaWEB
- web.archive.org/web/20200804224345/https://www.securityfocus.com/bid/64513ghsaWEB
News mentions
0No linked articles in our index yet.