ruby: entity expansion DoS vulnerability in REXML
Published Apr 9, 2013
5.0
MEDIUMCVSS 2.0
EPSS 6.73%
Description
lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.
Affected products
No data.
Configuration 1
- ≤ 1.9.3
- 1.9
- 1.9.1
- 1.9.2
- 1.9.3
- 1.9.3
- 1.9.3
- 1.9.3
- 1.9.3
- 1.9.3
No data.
Fuse ESB Enterprise 7.1.0
n/a
Fixed · RHSA-2013:1028
Red Hat Enterprise Linux 5
ruby-0:1.8.5-29.el5_9
Fixed · RHSA-2013:0611
Red Hat Enterprise Linux 6
ruby-0:1.8.7.352-10.el6_4
Fixed · RHSA-2013:0612
Red Hat Hardened Images
ruby3-3-main-3.3.10-23.1.hum1
Fixed · RHSA-2026:7305
Red Hat Hardened Images
ruby3-4-main-3.4.8-31.1.hum1
Fixed · RHSA-2026:7307
Red Hat Hardened Images
ruby4-0-main-4.0.0-33.3.hum1
Fixed · RHSA-2026:8838
Red Hat JBoss Fuse 6.0
n/a
Fixed · RHSA-2013:1185
Red Hat JBoss SOA Platform 5.3
n/a
Fixed · RHSA-2013:1147
OpenShift Enterprise 1
ruby193-ruby
Affected
Red Hat JBoss SOA Platform 4
jruby
Will not fix
Red Hat JBoss SOA Platform 5
jruby
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Fuse ESB Enterprise 7.1.0 | n/a | Fixed | RHSA-2013:1028 |
| Red Hat Enterprise Linux 5 | ruby-0:1.8.5-29.el5_9 | Fixed | RHSA-2013:0611 |
| Red Hat Enterprise Linux 6 | ruby-0:1.8.7.352-10.el6_4 | Fixed | RHSA-2013:0612 |
| Red Hat Hardened Images | ruby3-3-main-3.3.10-23.1.hum1 | Fixed | RHSA-2026:7305 |
| Red Hat Hardened Images | ruby3-4-main-3.4.8-31.1.hum1 | Fixed | RHSA-2026:7307 |
| Red Hat Hardened Images | ruby4-0-main-4.0.0-33.3.hum1 | Fixed | RHSA-2026:8838 |
| Red Hat JBoss Fuse 6.0 | n/a | Fixed | RHSA-2013:1185 |
| Red Hat JBoss SOA Platform 5.3 | n/a | Fixed | RHSA-2013:1147 |
| OpenShift Enterprise 1 | ruby193-ruby | Affected | n/a |
| Red Hat JBoss SOA Platform 4 | jruby | Will not fix | n/a |
| Red Hat JBoss SOA Platform 5 | jruby | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (28)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702525 x_refsource_MISC
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00015.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00034.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00036.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2013-0611.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-0612.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-1028.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-1147.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/52783 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/52902 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=39384 x_refsource_CONFIRM
- http://www.debian.org/security/2013/dsa-2738 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2013/dsa-2809 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:124 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2013/03/06/5 mailing-listx_refsource_MLIST
- http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html x_refsource_CONFIRM
- http://www.ruby-lang.org/en/news/2013/02/22/rexml-dos-2013-02-22/ x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/58141 vdb-entryx_refsource_BID
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2013&m=slackware-security.426862 vendor-advisoryx_refsource_SLACKWARE
- http://www.ubuntu.com/usn/USN-1780-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-1821 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=914716 x_refsource_MISCIssue Tracking
- https://github.com/advisories/GHSA-hgg7-cghq-xhf4 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-1821
- https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0092 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2013-1821
- https://www.jruby.org/2013/02/21/jruby-1-7-3.html
Change history (0)
No recorded changes yet.