7.8

CVE-2008-3656

Exploit

Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ruby-langRuby Version <= 1.8.5
Ruby-langRuby Version1.6.8
Ruby-langRuby Version1.8.0
Ruby-langRuby Version1.8.1
Ruby-langRuby Version1.8.1 Update-9
Ruby-langRuby Version1.8.2
Ruby-langRuby Version1.8.2 Updatepreview2
Ruby-langRuby Version1.8.2 Updatepreview3
Ruby-langRuby Version1.8.2 Updatepreview4
Ruby-langRuby Version1.8.3
Ruby-langRuby Version1.8.3 Updatepreview1
Ruby-langRuby Version1.8.3 Updatepreview2
Ruby-langRuby Version1.8.3 Updatepreview3
Ruby-langRuby Version1.8.4
Ruby-langRuby Version1.8.4 Updatepreview1
Ruby-langRuby Version1.8.4 Updatepreview2
Ruby-langRuby Version1.8.4 Updatepreview3
Ruby-langRuby Version1.8.5 Updatep11
Ruby-langRuby Version1.8.5 Updatep113
Ruby-langRuby Version1.8.5 Updatep115
Ruby-langRuby Version1.8.5 Updatep12
Ruby-langRuby Version1.8.5 Updatep2
Ruby-langRuby Version1.8.5 Updatep35
Ruby-langRuby Version1.8.5 Updatepreview1
Ruby-langRuby Version1.8.5 Updatepreview2
Ruby-langRuby Version1.8.5 Updatepreview3
Ruby-langRuby Version1.8.5 Updatepreview4
Ruby-langRuby Version1.8.5 Updatepreview5
Ruby-langRuby Version1.8.6
Ruby-langRuby Version1.8.6 Updatep110
Ruby-langRuby Version1.8.6 Updatep114
Ruby-langRuby Version1.8.6 Updatepreview1
Ruby-langRuby Version1.8.6 Updatepreview2
Ruby-langRuby Version1.8.6 Updatepreview3
Ruby-langRuby Version1.8.7
Ruby-langRuby Version1.8.7 Updatep17
Ruby-langRuby Version1.8.7 Updatep22
Ruby-langRuby Version1.8.7 Updatep71
Ruby-langRuby Version1.8.7 Updatepreview1
Ruby-langRuby Version1.8.7 Updatepreview2
Ruby-langRuby Version1.8.7 Updatepreview3
Ruby-langRuby Version1.8.7 Updatepreview4
Ruby-langRuby Version1.9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 75.85% 0.989
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C