[PLSA 2008-35] Ruby: Denial of Service
- Severity: 3
- Type: Remote
- Release Date: 2008-09-01
Summary
A vulnerability has been reported in Ruby, which can be exploited by malicious people to cause a DoS (Denial of Service).Description
The vulnerability is caused due to an error in the REXML library when processing recursively nested XML entities. This can be exploited to cause a DoS via a specially crafted XML document.
Note: This vulnerability found by Luka Treiber and Mitja Kolsek of ACROS Security.
Packages
Pardus 2008
- ruby, all before 1.8.7_p72-17-5
- ruby-mode, all before 1.8.7_p72-17-5
Pardus 2007
- ruby, all before 1.8.7_p72-17-14
- ruby-mode, all before 1.8.7_p72-17-5
Resolution
There are update(s) for ruby, ruby-mode. You can update them via Package Manager or with a single command from console:
Pardus 2008
pisi up ruby ruby-mode
Pardus 2007
pisi up ruby ruby-mode