CVE Vulnerabilities

CVE-2015-3227

Published: Jul 26, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

Affected Software

NameVendorStart VersionEnd Version
OpensuseOpensuse13.1 (including)13.1 (including)
OpensuseOpensuse13.2 (including)13.2 (including)
RailsUbuntuvivid*
RailsUbuntuwily*
Rails-4.0Ubuntuupstream*
Rails-4.0Ubuntuutopic*
Ruby-actionpack-2.3Ubuntuprecise*
Ruby-actionpack-2.3Ubuntuupstream*
Ruby-activerecord-2.3Ubuntuprecise*
Ruby-activerecord-2.3Ubuntuupstream*
Ruby-activesupport-2.3Ubuntuprecise*
Ruby-activesupport-2.3Ubuntuupstream*
Ruby-activesupport-3.2Ubuntutrusty*
Ruby-activesupport-3.2Ubuntuupstream*
Ruby-rails-2.3Ubuntuprecise*
Ruby-rails-2.3Ubuntuupstream*

References