CVE-2013-1821
ruby1.8 - several
EPSS 6.7%
描述
When reading text nodes from an XML document, the REXML parser can be coerced in to allocating extremely large string objects which can consume all of the memory on a machine, causing a denial of service. Jruby resolves this bug in version 1.7.3 as noted in https://www.jruby.org/2013/02/21/jruby-1-7-3.html
如何修補 CVE-2013-1821
要修補 CVE-2013-1821,請將受影響套件升級到下列已修補版本。
- Debian/ruby1.8—升級至 1.8.7.302-2squeeze2 或更新版本
- Debian/ruby1.9.1—升級至 1.9.2.0-2+deb6u1 或更新版本
- Maven/org.jruby:jruby—升級至 1.7.3 或更新版本
CVE-2013-1821 正在被利用嗎?
中等 — EPSS 為 6.7%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 1.8.7.302-2squeeze2
- from 0, < 1.9.2.0-2+deb6u1
- from 0, < 1.7.3