Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 11: DLA-4018-1 moderate: ruby2.7 multiple DoS vulnerabilities

debian lts
Calendar Grey January 18, 2025
Dist Debian Esm H88
Numerous vulnerabilities in ruby2.7 resolved in Debian LTS Advisory DLA-4018-1 released on January 17, 2025.
Multiple vulnerabilities were found in ruby a popular programming language

Summary

CVE-2024-35176

The REXML gem has a Denial of Service (DoS) vulnerability
when it parses an XML that has many `<`s in
an attribute value. Those who need to parse
untrusted XMLs may be impacted to this vulnerability.

CVE-2024-39908

The REXML gem has some Denial of Service (DoS) vulnerabilities
when it parses an XML that has many specific characters such
as `<`, `0` and `%>`. If you need to parse untrusted XMLs,
you many be impacted to these vulnerabilities.

CVE-2024-41123

The REXML gem has some Denial of Service (DoS) vulnerabilities
when it parses an XML that has many specific characters
such as whitespace character, >] and ]>.
If you need to parse untrusted XMLs, you may be impacted
to these vulnerabilities.

CVE-2024-41946

The REXML gem had a Denial of Service (DoS) vulnerability
when it parses an XML that has many entity expansions
with SAX2 or pull parser API.

CVE-2024-43398

REXML is an XML toolkit for Ruby.

Read the Full Advisory


Package: ruby2.7
Version: 2.7.4-1+deb11u3
CVE ID: CVE-2024-35176 CVE-2024-39908 CVE-2024-41123 CVE-2024-41946

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here