Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-28756
Description:A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2023.3408   1.3.6.1.4.1.25623.1.1.2.2023.1828   1.3.6.1.4.1.25623.1.1.2.2023.2341   1.3.6.1.4.1.25623.1.1.2.2023.1810   1.3.6.1.4.1.25623.1.1.2.2023.2321   1.3.6.1.4.1.25623.1.1.1.2.2023.3447  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-28756
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/
https://security.gentoo.org/glsa/202401-27
https://github.com/ruby/time/releases/
https://www.ruby-lang.org/en/downloads/releases/
https://www.ruby-lang.org/en/news/2022/12/25/ruby-3-2-0-released/
https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html




© 1998-2025 E-Soft Inc. All rights reserved.