rubygems: version regex algorithmic complexity vulnerability, incomplete CVE-2013-4287 fix
Published Oct 17, 2013
4.3
MEDIUMCVSS 2.0
EPSS 1.69%
Description
Algorithmic complexity vulnerability in Gem::Version::ANCHORED_VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.2, 1.8.24 through 1.8.26, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression. NOTE: this issue is due to an incomplete fix for CVE-2013-4287.
Affected products
No data.
Configuration 1
- ≤ 1.8.23
- 1.8.0
- 1.8.1
- 1.8.2
- 1.8.3
- 1.8.4
- 1.8.5
- 1.8.6
- 1.8.7
- 1.8.8
- 1.8.9
- 1.8.10
- 1.8.11
- 1.8.12
- 1.8.13
- 1.8.14
- 1.8.15
- 1.8.16
- 1.8.17
- 1.8.18
- 1.8.19
- 1.8.20
- 1.8.21
- 1.8.22
- 1.8.24
- 1.8.25
- 1.8.26
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
Configuration 2
- 1.9
- 1.9.1
- 1.9.2
- 1.9.3
- 1.9.3
- 1.9.3
- 1.9.3
- 1.9.3
- 1.9.3
- 1.9.3
- 1.9.3
- 1.9.3
- 1.9.3
- 2.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
No data.
CloudForms Management Engine 5
rubygems
Not affected
OpenShift Enterprise 1
ruby193-ruby
Not affected
OpenShift Enterprise 1
rubygems
Not affected
Red Hat Enterprise Linux 6
rubygems
Not affected
Red Hat Enterprise Linux 7
ruby
Not affected
Red Hat Enterprise MRG 2
rubygems
Not affected
Red Hat OpenStack Platform 3
ruby193-rubygems
Not affected
Red Hat Satellite 6
ruby193-rubygems
Not affected
Red Hat Satellite 6
rubygems
Not affected
Red Hat Software Collections
ruby193-ruby
Not affected
Red Hat Subscription Asset Manager
rubygems
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | rubygems | Not affected | n/a |
| OpenShift Enterprise 1 | ruby193-ruby | Not affected | n/a |
| OpenShift Enterprise 1 | rubygems | Not affected | n/a |
| Red Hat Enterprise Linux 6 | rubygems | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ruby | Not affected | n/a |
| Red Hat Enterprise MRG 2 | rubygems | Not affected | n/a |
| Red Hat OpenStack Platform 3 | ruby193-rubygems | Not affected | n/a |
| Red Hat Satellite 6 | ruby193-rubygems | Not affected | n/a |
| Red Hat Satellite 6 | rubygems | Not affected | n/a |
| Red Hat Software Collections | ruby193-ruby | Not affected | n/a |
| Red Hat Subscription Asset Manager | rubygems | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of rubygems as shipped with various Red Hat products.
References (13)
- http://blog.rubygems.org/2013/09/24/CVE-2013-4363.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.openwall.com/lists/oss-security/2013/09/14/3 mailing-listx_refsource_MLISTPatch
- http://www.openwall.com/lists/oss-security/2013/09/18/8 mailing-listx_refsource_MLISTPatch
- http://www.openwall.com/lists/oss-security/2013/09/20/1 mailing-listx_refsource_MLISTPatch
- https://access.redhat.com/security/cve/CVE-2013-4363 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1009720 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3436 Advisory
- https://github.com/advisories/GHSA-9qvm-2vhf-q649 Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubygems-update/CVE-2013-4363.yml
- https://nvd.nist.gov/vuln/detail/CVE-2013-4363
- https://puppet.com/security/cve/cve-2013-4363 x_refsource_CONFIRM
- https://web.archive.org/web/20170331150441/https://puppet.com/security/cve/cve-2013-4363
- https://www.cve.org/CVERecord?id=CVE-2013-4363
| Link | Providers | Tags |
|---|---|---|
| http://blog.rubygems.org/2013/09/24/CVE-2013-4363.html | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.openwall.com/lists/oss-security/2013/09/14/3 | mailing-listx_refsource_MLISTPatch | |
| http://www.openwall.com/lists/oss-security/2013/09/18/8 | mailing-listx_refsource_MLISTPatch | |
| http://www.openwall.com/lists/oss-security/2013/09/20/1 | mailing-listx_refsource_MLISTPatch | |
| https://access.redhat.com/security/cve/CVE-2013-4363 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1009720 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3436 | Advisory | |
| https://github.com/advisories/GHSA-9qvm-2vhf-q649 | Advisory | |
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubygems-update/CVE-2013-4363.yml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2013-4363 | ||
| https://puppet.com/security/cve/cve-2013-4363 | x_refsource_CONFIRM | |
| https://web.archive.org/web/20170331150441/https://puppet.com/security/cve/cve-2013-4363 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-4363 |
Change history (0)
No recorded changes yet.