Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hj56-84jw-67h6

Опубликовано: 23 июн. 2021
Источник: github
Github: Прошло ревью
CVSS4: 6.3
CVSS3: 3.7

Описание

Potential Denial-of-Service in bindata

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10, bindata improved the creation time of Bits and Integers.

Пакеты

Наименование

bindata

rubygems
Затронутые версииВерсия исправления

< 2.4.10

2.4.10

EPSS

Процентиль: 61%
0.00426
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 3.7
ubuntu
почти 4 года назад

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
nvd
почти 4 года назад

In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers.

CVSS3: 3.7
debian
почти 4 года назад

In the bindata RubyGem before version 2.4.10 there is a potential deni ...

CVSS3: 3.7
fstec
около 4 лет назад

Уязвимость декларативного способа чтения и записи бинарных форматов файлов BinData, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 61%
0.00426
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-400