Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dkubb

#34622of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2013-3401
7.5
2013-04-09
Ruby · Extlib · CVE-2013-1802
**Name of the Vulnerable Software and Affected Versions** extlib gem versions 0.9.15 and earlier **Description** The issue is related to the improper restriction of casts of string values, which could allow remote attackers to conduct object-injection attacks, execute arbitrary code, or cause a denial of service by consuming memory and CPU. This is achieved by leveraging Action Pack support for YAML type conversion or Symbol type conversion. **Recommendations** For extlib gem versions 0.9.15 and earlier, update to a version later than 0.9.15 to resolve the issue.