Описание
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ruby-openid | fixed | 2.1.8debian-6 | package | |
| libopenid-ruby | removed | package | ||
| libopenid-ruby | fixed | 2.1.8debian-1+squeeze1 | squeeze | package |
EPSS
Процентиль: 67%
0.00531
Низкий
Связанные уязвимости
ubuntu
около 12 лет назад
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
nvd
около 12 лет назад
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
EPSS
Процентиль: 67%
0.00531
Низкий