PT-2008-6898 · Ruby+2 · Libruby1.9+3

Published

1970-01-01

·

Updated

2018-10-03

·

CVE-2008-3790

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libruby1.9 versions 1.8.6 through 1.8.6-p287 libruby1.9 versions 1.8.7 through 1.8.7-p72 libruby1.9 versions 1.9
Description The issue is related to multiple vulnerabilities in the libruby1.9 package of the Debian GNU/Linux operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Specifically, the REXML module in Ruby allows context-dependent attackers to cause a denial of service via an XML document with recursively nested entities, also known as an "XML entity explosion."
Recommendations For versions 1.8.6 through 1.8.6-p287, consider updating to a version outside of this range to mitigate the risk. For versions 1.8.7 through 1.8.7-p72, consider updating to a version outside of this range to mitigate the risk. For version 1.9, consider updating to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting the use of the REXML module until a patch is available.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01941
BDU:2015-01942
BDU:2015-01943
CVE-2008-3790
DSA-1651-1
DSA-1652-1
RHSA-2008:0897
RHSA-2008_0897

Affected Products

Debian
Rexml
Red Hat
Libruby1.9