Ruby CVE-2014-8080 XML External Entity Denial of Service Vulnerability
BID:70935
Info
Ruby CVE-2014-8080 XML External Entity Denial of Service Vulnerability
| Bugtraq ID: | 70935 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8080 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2014 12:00AM |
| Updated: | Jul 05 2016 09:28PM |
| Credit: | Willis Vandevanter |
| Vulnerable: |
Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 Apple Mac Os X 10.7.4 Apple Mac Os X 10.7.3 Apple Mac Os X 10.7.1 |
| Not Vulnerable: | |
Discussion
Ruby CVE-2014-8080 XML External Entity Denial of Service Vulnerability
Ruby is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition.
The following versions are vulnerable:
Ruby 1.9 versions prior to 1.9.3-p550
Ruby 2.0 versions prior to 2.0.0-p594
Ruby 2.1 versions prior to 2.1.4
Ruby is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition.
The following versions are vulnerable:
Ruby 1.9 versions prior to 1.9.3-p550
Ruby 2.0 versions prior to 2.0.0-p594
Ruby 2.1 versions prior to 2.1.4
Solution / Fix
Ruby CVE-2014-8080 XML External Entity Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Ruby CVE-2014-8080 XML External Entity Denial of Service Vulnerability
References:
References:
- CVE-2014-8080: Denial of Service XML Expansion (Ruby-Lang)
- Oracle Linux Bulletin - January 2016 (Oracle)
- Ruby-Lang Homepage (Ruby-Lang)