Lucene search

K
nvd[email protected]NVD:CVE-2013-4287
HistoryOct 17, 2013 - 11:55 p.m.

CVE-2013-4287

2013-10-1723:55:04
CWE-310
web.nvd.nist.gov
7

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

High

EPSS

0.018

Percentile

88.3%

Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression.

Affected configurations

Nvd
Node
redhatenterprise_linuxMatch6.0
Node
rubygemsrubygemsRange1.8.23
OR
rubygemsrubygemsMatch1.8.0
OR
rubygemsrubygemsMatch1.8.1
OR
rubygemsrubygemsMatch1.8.2
OR
rubygemsrubygemsMatch1.8.3
OR
rubygemsrubygemsMatch1.8.4
OR
rubygemsrubygemsMatch1.8.5
OR
rubygemsrubygemsMatch1.8.6
OR
rubygemsrubygemsMatch1.8.7
OR
rubygemsrubygemsMatch1.8.8
OR
rubygemsrubygemsMatch1.8.9
OR
rubygemsrubygemsMatch1.8.10
OR
rubygemsrubygemsMatch1.8.11
OR
rubygemsrubygemsMatch1.8.12
OR
rubygemsrubygemsMatch1.8.13
OR
rubygemsrubygemsMatch1.8.14
OR
rubygemsrubygemsMatch1.8.15
OR
rubygemsrubygemsMatch1.8.16
OR
rubygemsrubygemsMatch1.8.17
OR
rubygemsrubygemsMatch1.8.18
OR
rubygemsrubygemsMatch1.8.19
OR
rubygemsrubygemsMatch1.8.20
OR
rubygemsrubygemsMatch1.8.21
OR
rubygemsrubygemsMatch1.8.22
OR
rubygemsrubygemsMatch1.8.24
OR
rubygemsrubygemsMatch1.8.25
OR
rubygemsrubygemsMatch2.0.0
OR
rubygemsrubygemsMatch2.0.1
OR
rubygemsrubygemsMatch2.0.2
OR
rubygemsrubygemsMatch2.0.3
OR
rubygemsrubygemsMatch2.0.4
OR
rubygemsrubygemsMatch2.0.5
OR
rubygemsrubygemsMatch2.0.6
OR
rubygemsrubygemsMatch2.0.7
OR
rubygemsrubygemsMatch2.1.0rc1
OR
rubygemsrubygemsMatch2.1.0rc2
Node
ruby-langrubyMatch1.9
OR
ruby-langrubyMatch1.9.1
OR
ruby-langrubyMatch1.9.2
OR
ruby-langrubyMatch1.9.3
OR
ruby-langrubyMatch1.9.3p0
OR
ruby-langrubyMatch1.9.3p125
OR
ruby-langrubyMatch1.9.3p194
OR
ruby-langrubyMatch1.9.3p286
OR
ruby-langrubyMatch1.9.3p383
OR
ruby-langrubyMatch1.9.3p385
OR
ruby-langrubyMatch1.9.3p392
OR
ruby-langrubyMatch1.9.3p426
OR
ruby-langrubyMatch1.9.3p429
OR
ruby-langrubyMatch2.0
OR
ruby-langrubyMatch2.0.0
OR
ruby-langrubyMatch2.0.0p0
OR
ruby-langrubyMatch2.0.0p195
OR
ruby-langrubyMatch2.0.0p247
OR
ruby-langrubyMatch2.0.0preview1
OR
ruby-langrubyMatch2.0.0preview2
OR
ruby-langrubyMatch2.0.0rc1
OR
ruby-langrubyMatch2.0.0rc2
VendorProductVersionCPE
redhatenterprise_linux6.0cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
rubygemsrubygems*cpe:2.3:a:rubygems:rubygems:*:*:*:*:*:*:*:*
rubygemsrubygems1.8.0cpe:2.3:a:rubygems:rubygems:1.8.0:*:*:*:*:*:*:*
rubygemsrubygems1.8.1cpe:2.3:a:rubygems:rubygems:1.8.1:*:*:*:*:*:*:*
rubygemsrubygems1.8.2cpe:2.3:a:rubygems:rubygems:1.8.2:*:*:*:*:*:*:*
rubygemsrubygems1.8.3cpe:2.3:a:rubygems:rubygems:1.8.3:*:*:*:*:*:*:*
rubygemsrubygems1.8.4cpe:2.3:a:rubygems:rubygems:1.8.4:*:*:*:*:*:*:*
rubygemsrubygems1.8.5cpe:2.3:a:rubygems:rubygems:1.8.5:*:*:*:*:*:*:*
rubygemsrubygems1.8.6cpe:2.3:a:rubygems:rubygems:1.8.6:*:*:*:*:*:*:*
rubygemsrubygems1.8.7cpe:2.3:a:rubygems:rubygems:1.8.7:*:*:*:*:*:*:*
Rows per page:
1-10 of 591

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

High

EPSS

0.018

Percentile

88.3%