The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ruby | Ruby-lang | * | 1.9.2 (including) |
Ruby1.8 | Ubuntu | precise | * |
Ruby1.9.1 | Ubuntu | upstream | * |