CVE-2013-1821
Publication date 7 March 2013
Last updated 24 July 2024
Ubuntu priority
lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
ruby1.8 | ||
ruby1.9.1 | ||
Patch details
Package | Patch details |
---|---|
ruby1.9.1 |
References
Related Ubuntu Security Notices (USN)
- USN-1780-1
- Ruby vulnerability
- 25 March 2013