Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-4287
Description:Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression.
Test IDs: 1.3.6.1.4.1.25623.1.0.866906   1.3.6.1.4.1.25623.1.0.120194   1.3.6.1.4.1.25623.1.0.866909  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-4287
http://www.openwall.com/lists/oss-security/2013/09/10/1
RedHat Security Advisories: RHSA-2013:1427
http://rhn.redhat.com/errata/RHSA-2013-1427.html
RedHat Security Advisories: RHSA-2013:1441
http://rhn.redhat.com/errata/RHSA-2013-1441.html
RedHat Security Advisories: RHSA-2013:1523
http://rhn.redhat.com/errata/RHSA-2013-1523.html
RedHat Security Advisories: RHSA-2013:1852
http://rhn.redhat.com/errata/RHSA-2013-1852.html
RedHat Security Advisories: RHSA-2014:0207
http://rhn.redhat.com/errata/RHSA-2014-0207.html
http://secunia.com/advisories/55381




© 1998-2025 E-Soft Inc. All rights reserved.