[PLSA 2008-35] Ruby: Denial of Service

Summary

A vulnerability has been reported in Ruby, which can be exploited by malicious people to cause a DoS (Denial of Service).

Description

The vulnerability is caused due to an error in the REXML library when processing recursively nested XML entities. This can be exploited to cause a DoS via a specially crafted XML document.

Note: This vulnerability found by Luka Treiber and Mitja Kolsek of ACROS Security.

Packages

Pardus 2008

Pardus 2007

Resolution

There are update(s) for ruby, ruby-mode. You can update them via Package Manager or with a single command from console:

Pardus 2008

pisi up ruby ruby-mode 

Pardus 2007

pisi up ruby ruby-mode 

References