CVE-2014-8080
03.11.2014, 16:55
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.Enginsight
| Vendor | Product | Version |
|---|---|---|
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 14.10 |
| ruby-lang | ruby | 𝑥 ≤ 1.9.3 |
| ruby-lang | ruby | 1.9.3 |
| ruby-lang | ruby | 1.9.3:p0 |
| ruby-lang | ruby | 1.9.3:p125 |
| ruby-lang | ruby | 1.9.3:p194 |
| ruby-lang | ruby | 1.9.3:p286 |
| ruby-lang | ruby | 1.9.3:p383 |
| ruby-lang | ruby | 1.9.3:p385 |
| ruby-lang | ruby | 1.9.3:p392 |
| ruby-lang | ruby | 1.9.3:p426 |
| ruby-lang | ruby | 1.9.3:p429 |
| ruby-lang | ruby | 1.9.3:p448 |
| ruby-lang | ruby | 1.9.3:p545 |
| ruby-lang | ruby | 1.9.3:p547 |
| ruby-lang | ruby | 2.0.0 |
| ruby-lang | ruby | 2.0.0:p0 |
| ruby-lang | ruby | 2.0.0:p195 |
| ruby-lang | ruby | 2.0.0:p247 |
| ruby-lang | ruby | 2.0.0:p451 |
| ruby-lang | ruby | 2.0.0:p481 |
| ruby-lang | ruby | 2.0.0:p576 |
| ruby-lang | ruby | 2.1.1 |
| ruby-lang | ruby | 2.1.2 |
| ruby-lang | ruby | 2.1.3 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ruby1.8 |
| ||||||||||||||
| ruby1.9 |
| ||||||||||||||
| ruby1.9.1 |
| ||||||||||||||
| ruby2.0 |
| ||||||||||||||
| ruby2.1 |
|
References