PT-2008-6901 · Ruby+1 · Ruby+1

Laurent Gaffiã©

·

Publicado

1970-01-01

·

Atualizado

2018-10-03

·

CVE-2008-3443

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Ruby versions 1.8.5 and earlier Ruby versions 1.8.6 through 1.8.6-p286 Ruby versions 1.8.7 through 1.8.7-p71 Ruby versions 1.9 through r18423
Description The issue concerns multiple vulnerabilities in the Ruby package, which can lead to a denial of service, causing a disruption in the availability of protected information. These vulnerabilities can be exploited remotely, potentially through a Ruby socket. The regular expression engine in affected Ruby versions allows remote attackers to cause an infinite loop and crash via multiple long requests, related to memory allocation failure.
Recommendations For Ruby version 1.8.5 and earlier, update to a version later than 1.8.5 to resolve the issue. For Ruby versions 1.8.6 through 1.8.6-p286, update to a version later than 1.8.6-p286 to resolve the issue. For Ruby versions 1.8.7 through 1.8.7-p71, update to a version later than 1.8.7-p71 to resolve the issue. For Ruby versions 1.9 through r18423, update to a version later than r18423 to resolve the issue.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01949
BDU:2015-01950
BDU:2015-01951
CVE-2008-3443
DSA-1695-1
RHSA-2008:0895
RHSA-2008:0896
RHSA-2008:0897
RHSA-2008_0897

Produtos afetados

Red Hat
Ruby