PT-2015-4240 · Ruby · Raven-Ruby

David Cramer

·

Published

2015-01-20

·

Updated

2018-08-13

·

CVE-2014-9490

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions raven-ruby gem versions prior to 0.12.2
Description The issue allows remote attackers to cause a denial of service via a large exponent value in a scientific number, specifically targeting the numtok function in lib/raven/okjson.rb.
Recommendations For versions prior to 0.12.2, update to version 0.12.2 or later to resolve the issue. As a temporary workaround, consider restricting input to the numtok function to prevent large exponent values in scientific numbers.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9490
GHSA-C9C5-9FPR-M882

Affected Products

Raven-Ruby