Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-0306

Опубликовано: 09 янв. 2025
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby3.3not-affectedpackage
ruby3.2removedpackage
ruby3.1fixed3.1.2-8.4package
ruby3.1ignoredbookwormpackage
ruby2.7removedpackage
ruby2.7ignoredbullseyepackage

Примечания

  • First upload of OpenSSL 3.2 to unstable was 3.2.1-3 on 04 Apr 2024

  • https://bugzilla.redhat.com/show_bug.cgi?id=2336100

  • https://people.redhat.com/~hkario/marvin/

  • Using OpenSSL/3.2.0 or later does not guarantee to mitigate the issue in all

  • cases, but at least when using the default provider. It will be always up to

  • the application to properly defend against this attack vector.

EPSS

Процентиль: 29%
0.00101
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
5 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
redhat
12 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
nvd
5 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
redos
3 месяца назад

Уязвимость ruby

CVSS3: 7.4
github
5 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

EPSS

Процентиль: 29%
0.00101
Низкий