Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3227

Опубликовано: 26 июл. 2015
Источник: debian
EPSS Низкий

Описание

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:4.2.4-2package
railsend-of-lifesqueezepackage
railsnot-affectedwheezypackage
ruby-activesupport-3.2removedpackage
ruby-activesupport-2.3removedpackage
ruby-activesupport-2.3end-of-lifewheezypackage

EPSS

Процентиль: 90%
0.04261
Низкий

Связанные уязвимости

ubuntu
около 11 лет назад

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

redhat
около 11 лет назад

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

nvd
около 11 лет назад

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

suse-cvrf
больше 10 лет назад

Security update for rubygem-activesupport-3_2

github
почти 9 лет назад

activesupport vulnerable to Denial of Service via large XML document depth

EPSS

Процентиль: 90%
0.04261
Низкий