CVE-2008-3790
Published: 27 August 2008
The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion."
Priority
Notes
Author | Note |
---|---|
jdstrand | PoC http://downloads.securityfocus.com/vulnerabilities/exploits/30802.rb |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3790
- http://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml/
- https://usn.ubuntu.com/usn/usn-651-1
- https://usn.ubuntu.com/usn/usn-691-1
- NVD
- Launchpad
- Debian