[go: up one dir, main page]

|
|
Log in / Subscribe / Register

rubygems: denial of service

Package(s):rubygems CVE #(s):CVE-2013-4363
Created:October 4, 2013 Updated:October 9, 2013
Description:

From the Fedora advisory:

Previously a security flow was found on rubygems for validating versions with a regular expression which is vulnerable to denial of service due to backtracking. Although this was thought to be fixed in the previous rubygems, the fix was found to be incomplete and the incompleteness is now assigned as CVE-2013-4363.

Alerts:
openSUSE openSUSE-SU-2013:1611-1 ruby19 2013-10-30
Oracle ELSA-2013-1441 rubygems 2013-10-18
Mageia MGASA-2013-0297 ruby-RubyGems 2013-10-10
Fedora FEDORA-2013-17662 rubygems 2013-10-04
Fedora FEDORA-2013-17649 rubygems 2013-10-04

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds