CVE-2013-1821

EPSS 25.7%

ruby1.9.1 - several

發布日:2022/5/17修改日:2026/3/9

描述

When reading text nodes from an XML document, the REXML parser can be coerced in to allocating extremely large string objects which can consume all of the memory on a machine, causing a denial of service. Jruby resolves this bug in version 1.7.3 as noted in https://www.jruby.org/2013/02/21/jruby-1-7-3.html

受影響套件(3)

參考連結(19)