CVE Vulnerabilities

CVE-2013-1812

Published: Dec 12, 2013 | Modified: Dec 13, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.

Affected Software

Name Vendor Start Version End Version
Fedora Fedoraproject 17 (including) 17 (including)
Fedora Fedoraproject 18 (including) 18 (including)
Libopenid-ruby Ubuntu lucid *
Libopenid-ruby Ubuntu oneiric *
Libopenid-ruby Ubuntu precise *
Libopenid-ruby Ubuntu upstream *
Ruby-openid Ubuntu quantal *
Ruby-openid Ubuntu upstream *

References