Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-0306

Опубликовано: 24 июн. 2024
Источник: redhat
CVSS3: 7.4

Описание

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

Отчет

More information about the Marvin Attack may be found at https://www.redhat.com/en/blog/marvin-attack.

Меры по смягчению последствий

See the following possible mitigations for this flaw:

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rubyOut of support scope
Red Hat Enterprise Linux 7rubyOut of support scope
Red Hat Enterprise Linux 8ruby:2.5/rubyOut of support scope
Red Hat Enterprise Linux 8ruby:3.1/rubyOut of support scope
Red Hat Enterprise Linux 8ruby:3.3/rubyNot affected
Red Hat Enterprise Linux 9rubyWill not fix
Red Hat Enterprise Linux 9ruby:3.1/rubyWill not fix
Red Hat Enterprise Linux 9ruby:3.3/rubyWill not fix
Red Hat Storage 3rubyAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 1 года назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
nvd
около 1 года назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
debian
около 1 года назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable ...

CVSS3: 7.4
github
около 1 года назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
fstec
больше 1 года назад

Уязвимость интерпретатора Ruby, связанная с использованием скрытых временных каналов для передачи данных, позволяющая нарушителю реализовать атаку Marvin

7.4 High

CVSS3