CVE-2014-6438
06.09.2017, 21:29
The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.Enginsight
Vendor | Product | Version |
---|---|---|
ruby-lang | ruby | 𝑥 ≤ 1.9.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ruby1.8 |
| ||||||||||||||||||
ruby1.9 |
| ||||||||||||||||||
ruby1.9.1 |
| ||||||||||||||||||
ruby2.0 |
| ||||||||||||||||||
ruby2.1 |
| ||||||||||||||||||
ruby2.2 |
| ||||||||||||||||||
ruby2.3 |
|
Common Weakness Enumeration
References