LWN.net Logo

rubygems: denial of service

Package(s):rubygems CVE #(s):CVE-2013-4363
Created:October 4, 2013 Updated:October 4, 2013
Description:

From the Fedora advisory:

Previously a security flow was found on rubygems for validating versions with a regular expression which is vulnerable to denial of service due to backtracking. Although this was thought to be fixed in the previous rubygems, the fix was found imcomplete and the imcompleteness is now assigned as CVE-2013-4363.

Alerts:
Fedora FEDORA-2013-17649 2013-10-04
Fedora FEDORA-2013-17662 2013-10-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds