Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-0306

Опубликовано: 09 янв. 2025
Источник: debian

Описание

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby3.3not-affectedpackage
ruby3.2removedpackage
ruby3.1fixed3.1.2-8.4package
ruby3.1ignoredbookwormpackage
ruby2.7removedpackage
ruby2.7ignoredbullseyepackage

Примечания

  • First upload of OpenSSL 3.2 to unstable was 3.2.1-3 on 04 Apr 2024

  • https://bugzilla.redhat.com/show_bug.cgi?id=2336100

  • https://people.redhat.com/~hkario/marvin/

  • Using OpenSSL/3.2.0 or later does not guarantee to mitigate the issue in all

  • cases, but at least when using the default provider. It will be always up to

  • the application to properly defend against this attack vector.

Связанные уязвимости

CVSS3: 7.4
ubuntu
11 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
redhat
больше 1 года назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
nvd
11 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
redos
9 месяцев назад

Уязвимость ruby

CVSS3: 7.4
github
11 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.