5
CVSSv2

CVE-2008-3443

Published: 14/08/2008 Updated: 03/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The regular expression engine (regex.c) in Ruby 1.8.5 and previous versions, 1.8.6 up to and including 1.8.6-p286, 1.8.7 up to and including 1.8.7-p71, and 1.9 through r18423 allows remote malicious users to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

Vulnerable Product Search on Vulmon Subscribe to Product

ruby-lang ruby 1.8.1

ruby-lang ruby 1.8.2

ruby-lang ruby 1.8.4

ruby-lang ruby 1.8.5

ruby-lang ruby 1.8.6

ruby-lang ruby 1.8.7

ruby-lang ruby 1.8.0

ruby-lang ruby 1.8.3

ruby-lang ruby 1.6.8

ruby-lang ruby 1.9.0

Vendor Advisories

Synopsis Moderate: ruby security update Type/Severity Security Advisory: Moderate Topic Updated ruby packages that fix various security issues are now availablefor Red Hat Enterprise Linux 21This update has been rated as having moderate security impact by the RedHat Security Response Team Descri ...
Synopsis Moderate: ruby security update Type/Severity Security Advisory: Moderate Topic Updated ruby packages that fix several security issues are now availablefor Red Hat Enterprise Linux 3This update has been rated as having moderate security impact by the RedHat Security Response Team Descript ...
Synopsis Moderate: ruby security update Type/Severity Security Advisory: Moderate Topic Updated ruby packages that fix several security issues are now availablefor Red Hat Enterprise Linux 4 and 5This update has been rated as having moderate security impact by the RedHat Security Response Team De ...
The regular expression engine of Ruby, a scripting language, contains a memory leak which can be triggered remotely under certain circumstances, leading to a denial of service condition (CVE-2008-3443) In addition, this security update addresses a regression in the REXML XML parser of the ruby18 package; the regression was introduced in DSA-1651- ...
Laurent Gaffie discovered that Ruby did not properly check for memory allocation failures If a user or automated system were tricked into running a malicious script, an attacker could cause a denial of service (CVE-2008-3443) ...
Akira Tagoh discovered a vulnerability in Ruby which lead to an integer overflow If a user or automated system were tricked into running a malicious script, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2008-2376) ...

Exploits

------------------------------------------------------- Language : Ruby Web Site: wwwruby-langorg Platform: All Bug: Remote Socket Memory Leak Products Affected: 18 series: - 185 and all prior versions - 186-p286 and all prior versions - 187-p71 and all prior versions 19 series - r18423 and all prior revisions Confirmed by the vend ...