Lucene search

K
redhatRedHatRHSA-2013:1523
HistoryNov 14, 2013 - 12:00 a.m.

(RHSA-2013:1523) Moderate: ruby193-ruby security update

2013-11-1400:00:00
access.redhat.com
20

EPSS

0.018

Percentile

88.3%

Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.
RubyGems is the Ruby standard for publishing and managing third-party
libraries.

It was discovered that the rubygems API validated version strings using an
unsafe regular expression. An application making use of this API to process
a version string from an untrusted source could be vulnerable to a denial
of service attack through CPU exhaustion. (CVE-2013-4287)

Red Hat would like to thank Rubygems upstream for reporting this
issue. Upstream acknowledges Damir Sharipov as the original reporter.

Users of Red Hat OpenStack 3.0 are advised to upgrade to these updated
packages, which correct this issue.