LWN.net Logo

ruby: denial of service

Package(s):ruby CVE #(s):CVE-2013-1821
Created:March 8, 2013 Updated:April 4, 2013
Description:

From the Red Hat advisory:

It was discovered that Ruby's REXML library did not properly restrict XML entity expansion. An attacker could use this flaw to cause a denial of service by tricking a Ruby application using REXML to read text nodes from specially-crafted XML content, which will result in REXML consuming large amounts of system memory.

Alerts:
Red Hat RHSA-2013:0611-01 2013-03-07
Red Hat RHSA-2013:0612-01 2013-03-07
CentOS CESA-2013:0611 2013-03-08
Scientific Linux SL-ruby-20130307 2013-03-07
CentOS CESA-2013:0611 2013-03-08
Oracle ELSA-2013-0611 2013-03-08
CentOS CESA-2013:0612 2013-03-09
Mageia MGASA-2013-0092 2013-03-16
Slackware SSA:2013-075-01 2013-03-16
Ubuntu USN-1780-1 2013-03-25
openSUSE openSUSE-SU-2013:0603-1 2013-04-03
openSUSE openSUSE-SU-2013:0614-1 2013-04-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds