CVE-2021-32823
Summary
| CVE | CVE-2021-32823 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-24 00:15:00 UTC |
| Updated | 2022-10-25 14:20:00 UTC |
| Description | In the bindata RubyGem before version 2.4.10 there is a potential denial-of-service vulnerability. In affected versions it is very slow for certain classes in BinData to be created. For example BinData::Bit100000, BinData::Bit100001, BinData::Bit100002, BinData::Bit<N>. In combination with <user_input>.constantize there is a potential for a CPU-based DoS. In version 2.4.10 bindata improved the creation time of Bits and Integers. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bindata | RubyGems.org | your community gem host | MISC | rubygems.org | |
| Improved creation time of Bits and Integers · dmendel/bindata@d99f050 · GitHub | CONFIRM | github.com | |
| Add advisory for bindata · Issue #476 · rubysec/ruby-advisory-db · GitHub | MISC | github.com | |
| GitLab Security Release: 13.12.2, 13.11.5, and 13.10.5 | GitLab | MISC | about.gitlab.com | |
| bindata/ChangeLog.rdoc at v2.4.10 · dmendel/bindata · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182918 Debian Security Update for ruby-bindata (CVE-2021-32823)