← Back

CVE-2013-4287

nvd nist
Published: Oct 17, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression.

Affected (59)

1 product
Enterprise Linux
1 product
Rubygems
1 product
Ruby
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Configuration B
36 vulnerable
Vulnerable SoftwareAffected Versions
Rubygems
Up to 1.8.23
Version 1.8.0
Version 1.8.10
Version 1.8.11
Version 1.8.12
Version 1.8.13
Version 1.8.14
Version 1.8.15
Version 1.8.16
Version 1.8.17
Version 1.8.18
Version 1.8.19
Version 1.8.1
Version 1.8.20
Version 1.8.21
Version 1.8.22
Version 1.8.24
Version 1.8.25
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.8.5
Version 1.8.6
Version 1.8.7
Version 1.8.8
Version 1.8.9
Version 2.0.0
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.1.0 rc1
Version 2.1.0 rc2
Configuration C
22 vulnerable
Vulnerable SoftwareAffected Versions
Ruby Lang
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.3 p0
Version 1.9.3 p125
Version 1.9.3 p194
Version 1.9.3 p286
Version 1.9.3 p383
Version 1.9.3 p385
Version 1.9.3 p392
Version 1.9.3 p426
Version 1.9.3 p429
Version 1.9
Version 2.0.0
Version 2.0.0 p0
Version 2.0.0 p195
Version 2.0.0 p247
Version 2.0.0 preview1
Version 2.0.0 preview2
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0

Related CWEs

References (18)

Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.