Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8080

Опубликовано: 03 нояб. 2014
Источник: debian
EPSS Низкий

Описание

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby1.8removedpackage
ruby1.9.1removedpackage
ruby2.0removedpackage
ruby2.1fixed2.1.4-1package

Примечания

  • https://www.ruby-lang.org/en/news/2014/10/27/rexml-dos-cve-2014-8080/

  • http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/?pathrev=48161

EPSS

Процентиль: 93%
0.09507
Низкий

Связанные уязвимости

ubuntu
почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

redhat
почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

nvd
почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

github
больше 3 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

oracle-oval
почти 11 лет назад

ELSA-2014-1911: ruby security update (MODERATE)

EPSS

Процентиль: 93%
0.09507
Низкий