← Back

CVE-2013-4363

nvd nist
Published: Oct 17, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Algorithmic complexity vulnerability in Gem::Version::ANCHORED_VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.2, 1.8.24 through 1.8.26, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression. NOTE: this issue is due to an incomplete fix for CVE-2013-4287.

Affected (71)

1 product
Rubygems
1 product
Ruby
Configuration A
49 vulnerable
Vulnerable SoftwareAffected Versions
Rubygems
Up to 1.8.23
Version 1.8.0
Version 1.8.10
Version 1.8.11
Version 1.8.12
Version 1.8.13
Version 1.8.14
Version 1.8.15
Version 1.8.16
Version 1.8.17
Version 1.8.18
Version 1.8.19
Version 1.8.1
Version 1.8.20
Version 1.8.21
Version 1.8.22
Version 1.8.24
Version 1.8.25
Version 1.8.26
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.8.5
Version 1.8.6
Version 1.8.7
Version 1.8.8
Version 1.8.9
Version 2.0.0
Version 2.0.0 preview2.1
Version 2.0.0 preview2.2
Version 2.0.0 preview2
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.0.9
Version 2.1.0
Version 2.1.0 rc1
Version 2.1.0 rc2
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Configuration B
22 vulnerable
Vulnerable SoftwareAffected Versions
Ruby Lang
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.3 p0
Version 1.9.3 p125
Version 1.9.3 p194
Version 1.9.3 p286
Version 1.9.3 p383
Version 1.9.3 p385
Version 1.9.3 p392
Version 1.9.3 p426
Version 1.9.3 p429
Version 1.9
Version 2.0.0
Version 2.0.0 p0
Version 2.0.0 p195
Version 2.0.0 p247
Version 2.0.0 preview1
Version 2.0.0 preview2
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0

Related CWEs

References (10)

Source: secalert@redhat.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.