Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3443

Опубликовано: 14 авг. 2008
Источник: nvd
CVSS2: 5
EPSS Средний

Описание

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ruby-lang:ruby:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.1:-9:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.2:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.2:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.2:preview4:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.3:preview1:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.3:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.3:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.4:preview1:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.4:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.4:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p11:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p113:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p114:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p115:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p12:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p231:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p35:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p52:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:preview1:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:preview4:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:preview5:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p110:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p111:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p114:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p230:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p286:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p36:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:preview1:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:p17:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:p22:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:p71:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:preview1:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:preview4:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.9.0:r18423:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.36765
Средний

5 Medium

CVSS2

Дефекты

CWE-399

Связанные уязвимости

ubuntu
около 17 лет назад

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

redhat
около 17 лет назад

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

debian
около 17 лет назад

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8 ...

github
больше 3 лет назад

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

fstec
почти 11 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 97%
0.36765
Средний

5 Medium

CVSS2

Дефекты

CWE-399