Sha256: 6ecbb3962071b98dae2a2705c0b1986448bdd1f7fd1f0eec60b74bf31a0682fa
Contents?: true
Size: 502 Bytes
Versions: 6
Compression:
Stored size: 502 Bytes
Contents
--- engine: ruby cve: 2008-3790 osvdb: 47753 url: http://www.osvdb.org/show/osvdb/47753 title: Ruby REXML Library Crafted XML Document Handling DoS date: 2008-08-25 description: | The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion." cvss_v2: 5.0 patched_versions: - ~> 1.8.7.160 - ">= 1.9.1"
Version data entries
6 entries across 6 versions & 2 rubygems