Medium severity5.5NVD Advisory· Published Feb 26, 2018· Updated Jun 17, 2026
CVE-2017-16229
CVE-2017-16229
Description
In the Ox gem 2.8.1 for Ruby, the process crashes with a stack-based buffer over-read in the read_from_str function in sax_buf.c when a crafted input is supplied to sax_parse.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
oxRubyGems | < 2.8.2 | 2.8.2 |
Affected products
2- cpe:2.3:a:ox_project:ox:2.8.1:*:*:*:*:ruby:*:*
Patches
Vulnerability mechanics
References
5- github.com/ohler55/ox/issues/195nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-wfwm-chj7-w59rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-16229ghsaADVISORY
- rubygems.org/gems/ox/versions/2.8.1nvdThird Party AdvisoryWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/ox/CVE-2017-16229.ymlghsaWEB
News mentions
0No linked articles in our index yet.