4.3
CVSSv2

CVE-2013-4287

Published: 17/10/2013 Updated: 22/04/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems prior to 1.8.23.1, 1.8.24 up to and including 1.8.25, 2.0.x prior to 2.0.8, and 2.1.x prior to 2.1.0, as used in Ruby 1.9.0 up to and including 2.0.0p247, allows remote malicious users to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux 6.0

rubygems rubygems 2.0.4

rubygems rubygems 2.0.5

rubygems rubygems 2.0.6

rubygems rubygems 1.8.10

rubygems rubygems 1.8.11

rubygems rubygems 1.8.18

rubygems rubygems 1.8.19

rubygems rubygems 1.8.6

rubygems rubygems 1.8.7

rubygems rubygems 2.1.0

rubygems rubygems 2.0.7

rubygems rubygems 1.8.24

rubygems rubygems 1.8.12

rubygems rubygems 1.8.13

rubygems rubygems 1.8.2

rubygems rubygems 1.8.20

rubygems rubygems 1.8.8

rubygems rubygems 1.8.9

rubygems rubygems 2.0.2

rubygems rubygems 2.0.3

rubygems rubygems 1.8.0

rubygems rubygems 1.8.1

rubygems rubygems 1.8.16

rubygems rubygems 1.8.17

rubygems rubygems 1.8.3

rubygems rubygems 1.8.4

rubygems rubygems 1.8.5

rubygems rubygems 2.0.0

rubygems rubygems 2.0.1

rubygems rubygems 1.8.25

rubygems rubygems

rubygems rubygems 1.8.14

rubygems rubygems 1.8.15

rubygems rubygems 1.8.21

rubygems rubygems 1.8.22

ruby-lang ruby 1.9.3

ruby-lang ruby 2.0

ruby-lang ruby 2.0.0

ruby-lang ruby 1.9.1

ruby-lang ruby 1.9.2

ruby-lang ruby 1.9

Vendor Advisories

Debian Bug report logs - #722361 rubygems: CVE-2013-4287: Algorithmic complexity vulnerability in RubyGems 207 and older Package: rubygems; Maintainer for rubygems is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Henri Salo <henri@nervfi> Date: Tue, 10 Sep 2013 1 ...
Synopsis Moderate: Red Hat Enterprise MRG Grid 24 security update Type/Severity Security Advisory: Moderate Topic Updated Grid component packages that fix multiple security issues are nowavailable for Red Hat Enterprise MRG 24 for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated thi ...
Synopsis Moderate: rubygems security update Type/Severity Security Advisory: Moderate Topic An updated rubygems package that fixes three security issues is nowavailable for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerabi ...
Synopsis Moderate: ruby193-ruby security update Type/Severity Security Advisory: Moderate Topic Updated ruby193-ruby packages that fix one security issue are now availablefor Red Hat Software Collections 1The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common V ...
Synopsis Moderate: ruby193-ruby security update Type/Severity Security Advisory: Moderate Topic Updated ruby193-ruby packages that fix one security issue are now availablefor Red Hat OpenStack 30The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerabil ...
Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/versionrb in RubyGems before 18231, 1824 through 1825, 20x before 208, and 21x before 210, as used in Ruby 190 through 200p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a lar ...
Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/versionrb in RubyGems before 18231, 1824 through 1825, 20x before 208, and 21x before 210, as used in Ruby 190 through 200p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a lar ...