Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3443

Опубликовано: 14 авг. 2008
Источник: nvd
CVSS2: 5
EPSS Средний

Описание

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ruby-lang:ruby:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.1:-9:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.2:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.2:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.2:preview4:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.3:preview1:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.3:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.3:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.4:preview1:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.4:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.4:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p11:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p113:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p114:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p115:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p12:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p231:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p35:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:p52:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:preview1:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:preview4:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.5:preview5:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p110:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p111:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p114:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p230:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p286:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:p36:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:preview1:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.6:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:p17:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:p22:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:p71:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:preview1:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:preview2:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:preview3:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7:preview4:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.9.0:r18423:*:*:*:*:*:*

EPSS

Процентиль: 96%
0.30956
Средний

5 Medium

CVSS2

Дефекты

CWE-399

Связанные уязвимости

ubuntu
почти 17 лет назад

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

redhat
почти 17 лет назад

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

debian
почти 17 лет назад

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8 ...

github
около 3 лет назад

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

fstec
больше 10 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 96%
0.30956
Средний

5 Medium

CVSS2

Дефекты

CWE-399