5

CVE-2008-3443

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

Data is provided by the National Vulnerability Database (NVD)
Ruby-langRuby Version1.6.8
Ruby-langRuby Version1.8.0
Ruby-langRuby Version1.8.1
Ruby-langRuby Version1.8.1 Update-9
Ruby-langRuby Version1.8.2
Ruby-langRuby Version1.8.2 Updatepreview2
Ruby-langRuby Version1.8.2 Updatepreview3
Ruby-langRuby Version1.8.2 Updatepreview4
Ruby-langRuby Version1.8.3
Ruby-langRuby Version1.8.3 Updatepreview1
Ruby-langRuby Version1.8.3 Updatepreview2
Ruby-langRuby Version1.8.3 Updatepreview3
Ruby-langRuby Version1.8.4
Ruby-langRuby Version1.8.4 Updatepreview1
Ruby-langRuby Version1.8.4 Updatepreview2
Ruby-langRuby Version1.8.4 Updatepreview3
Ruby-langRuby Version1.8.5
Ruby-langRuby Version1.8.5 Updatep11
Ruby-langRuby Version1.8.5 Updatep113
Ruby-langRuby Version1.8.5 Updatep114
Ruby-langRuby Version1.8.5 Updatep115
Ruby-langRuby Version1.8.5 Updatep12
Ruby-langRuby Version1.8.5 Updatep2
Ruby-langRuby Version1.8.5 Updatep231
Ruby-langRuby Version1.8.5 Updatep35
Ruby-langRuby Version1.8.5 Updatep52
Ruby-langRuby Version1.8.5 Updatepreview1
Ruby-langRuby Version1.8.5 Updatepreview2
Ruby-langRuby Version1.8.5 Updatepreview3
Ruby-langRuby Version1.8.5 Updatepreview4
Ruby-langRuby Version1.8.5 Updatepreview5
Ruby-langRuby Version1.8.6
Ruby-langRuby Version1.8.6 Updatep110
Ruby-langRuby Version1.8.6 Updatep111
Ruby-langRuby Version1.8.6 Updatep114
Ruby-langRuby Version1.8.6 Updatep230
Ruby-langRuby Version1.8.6 Updatep286
Ruby-langRuby Version1.8.6 Updatep36
Ruby-langRuby Version1.8.6 Updatepreview1
Ruby-langRuby Version1.8.6 Updatepreview2
Ruby-langRuby Version1.8.6 Updatepreview3
Ruby-langRuby Version1.8.7
Ruby-langRuby Version1.8.7 Updatep17
Ruby-langRuby Version1.8.7 Updatep22
Ruby-langRuby Version1.8.7 Updatep71
Ruby-langRuby Version1.8.7 Updatepreview1
Ruby-langRuby Version1.8.7 Updatepreview2
Ruby-langRuby Version1.8.7 Updatepreview3
Ruby-langRuby Version1.8.7 Updatepreview4
Ruby-langRuby Version1.9.0
Ruby-langRuby Version1.9.0 Updater18423
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 36.77% 0.97
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P