Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3227

Опубликовано: 26 июл. 2015
Источник: debian
EPSS Низкий

Описание

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:4.2.4-2package
railsend-of-lifesqueezepackage
railsnot-affectedwheezypackage
ruby-activesupport-3.2removedpackage
ruby-activesupport-2.3removedpackage
ruby-activesupport-2.3end-of-lifewheezypackage

EPSS

Процентиль: 85%
0.02683
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

redhat
больше 10 лет назад

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

nvd
больше 10 лет назад

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

suse-cvrf
около 10 лет назад

Security update for rubygem-activesupport-3_2

github
больше 8 лет назад

activesupport vulnerable to Denial of Service via large XML document depth

EPSS

Процентиль: 85%
0.02683
Низкий