Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v6rp-3r3v-hf4p

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Ruby OpenSSL DoS Vulnerability

The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string. The openssl gem that contains this module is patched in version 2.0.0.

Пакеты

Наименование

openssl

rubygems
Затронутые версииВерсия исправления

< 2.0.0

2.0.0

EPSS

Процентиль: 93%
0.10256
Средний

7.5 High

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string.

CVSS3: 5.3
redhat
около 8 лет назад

The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string.

CVSS3: 7.5
nvd
около 8 лет назад

The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string.

CVSS3: 7.5
debian
около 8 лет назад

The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2. ...

oracle-oval
больше 7 лет назад

ELSA-2018-0378: ruby security update (IMPORTANT)

EPSS

Процентиль: 93%
0.10256
Средний

7.5 High

CVSS3

Дефекты

CWE-119