Sitelet https://web.archive.org/web/20260225060556/https://github.com/github/advisory-database/pull/233
Skip to content

Comments

[GHSA-v6gp-9mmm-c6p5] Out-of-bounds Write in zlib affects Nokogiri#233

Closed
CharlesHoltjr wants to merge 1 commit intoCharlesHoltjr/advisory-improvement-233from
CharlesHoltjr-GHSA-v6gp-9mmm-c6p5
Closed

[GHSA-v6gp-9mmm-c6p5] Out-of-bounds Write in zlib affects Nokogiri#233
CharlesHoltjr wants to merge 1 commit intoCharlesHoltjr/advisory-improvement-233from
CharlesHoltjr-GHSA-v6gp-9mmm-c6p5

Conversation

@CharlesHoltjr
Copy link

Updates

  • CVSS
  • CWEs
  • Description
  • Severity

@github
Copy link
Collaborator

github commented Apr 27, 2022

Hi there @flavorjones! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our highly-trained Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions github-actions bot changed the base branch from main to CharlesHoltjr/advisory-improvement-233 April 27, 2022 14:44
@flavorjones
Copy link

@CharlesHoltjr The information in the original GHSA was taken from the CVE record for the zlib vulnerability, and still appears to be correct: https://nvd.nist.gov/vuln/detail/CVE-2018-25032

Can you help me understand what led you to submit this change proposal?

@darakian
Copy link
Contributor

darakian commented May 2, 2022

@CharlesHoltjr I'd also like to understand the justification for this change. If you would like to dispute the CVE severity the correct place to do that would be with mitre.

@advisory-database advisory-database bot closed this Jun 1, 2022
@github-actions github-actions bot deleted the CharlesHoltjr-GHSA-v6gp-9mmm-c6p5 branch June 1, 2022 22:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants