PT-2017-16930 · Ruby · Ruby+1
Published
2017-04-03
·
Updated
2017-04-11
·
CVE-2017-6181
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Onigmo (aka Oniguruma-mod) regular expression library as used in Ruby version 2.4.0
Description
The issue allows remote attackers to cause a denial of service, leading to deep recursion and application crash, via a crafted regular expression. This is due to a problem in the parse char class function in regparse.c.
Recommendations
For Ruby version 2.4.0, consider updating to a newer version that includes a fix for this issue, as the current version is affected by the denial of service vulnerability.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onigmo
Ruby