(Rails Issues Fix) Ruby REXML Recursive Entity Expansion Bug Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1020824 |
|
SecurityTracker URL: http://securitytracker.com/id/1020824
|
|
CVE Reference:
GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Sep 5 2008
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): prior to 2.0.4
|
Description:
A vulnerability was reported in Ruby. A remote user can cause denial of service conditions. Rails is affected.
A remote user can send specially crafted XML data to trigger a flaw in the REXML library and cause the target application to become unresponsive.
Luka Treiber and Mitja Kolsek of ACROS Security reported this vulnerability.
|
Impact:
A remote user can cause the target application to become unresponsive.
|
Solution:
Rails has issued a fixed version (2.0.4).
The Rails advisory is available at:
http://weblog.rubyonrails.org/2008/9/3/rails-2-0-4-maintenance-release
|
Cause:
State error
|
Underlying OS:
Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Fri, 5 Sep 2008 10:29:46 -0400
Subject: Rails
|
http://weblog.rubyonrails.org/2008/9/3/rails-2-0-4-maintenance-release
|
|