CVE-2013-1812
published 2013-12-12CVE-2013-1812: The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.13%
79.9th percentile
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-openid | < ruby-openid 2.1.8debian-6 (bookworm) | ruby-openid 2.1.8debian-6 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| janrain | ruby-openid | <= 2.2.1 | — |
| janrain | ruby-openid | — | — |
| janrain | ruby-openid | >= 0 < 2.1.8debian-6 | 2.1.8debian-6 |
| janrain | ruby-openid | >= 0 < 2.1.8debian-6 | 2.1.8debian-6 |
| janrain | ruby-openid | >= 0 < 2.1.8debian-6 | 2.1.8debian-6 |
| janrain | ruby-openid | >= 0 < 2.1.8debian-6 | 2.1.8debian-6 |
| janrain | ruby-openid | >= 0 < 2.2.2 | 2.2.2 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_redhat5.8MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Denial of service in ruby-openid
osv·2017-10-24
CVE-2013-1812 [MEDIUM] Denial of service in ruby-openid
Denial of service in ruby-openid
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
GHSA
Denial of service in ruby-openid
ghsa·2017-10-24
CVE-2013-1812 [MEDIUM] Denial of service in ruby-openid
Denial of service in ruby-openid
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
OSV
CVE-2013-1812: The ruby-openid gem before 2
osv·2013-12-12·CVSS 4.3
CVE-2013-1812 [MEDIUM] CVE-2013-1812: The ruby-openid gem before 2
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
Red Hat
Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
vendor_redhat·2013-02-19·CVSS 5.8
CVE-2013-0772 [MEDIUM] CWE-125 Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafted GIF image.
Statement: This issue has been addressed in firefox 24.2.0-ESR and thunderbird 24.2.0-ESR via RHSA-2013:1812 and RHSA-2013:1823.
Debian
CVE-2013-1812: ruby-openid - The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to caus...
vendor_debian·2013·CVSS 4.3
CVE-2013-1812 [MEDIUM] CVE-2013-1812: ruby-openid - The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to caus...
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
Scope: local
bookworm: resolved (fixed in 2.1.8debian-6)
bullseye: resolved (fixed in 2.1.8debian-6)
forky: resolved (fixed in 2.1.8debian-6)
sid: resolved (fixed in 2.1.8debian-6)
trixie: resolved (fixed in 2.1.8debian-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5614 Mozilla: Sandbox restrictions not applied to nested object elements (MFSA 2013-107)
bugzilla·2013-12-09·CVSS 4.3
CVE-2013-5614 [MEDIUM] CVE-2013-5614 Mozilla: Sandbox restrictions not applied to nested object elements (MFSA 2013-107)
CVE-2013-5614 Mozilla: Sandbox restrictions not applied to nested object elements (MFSA 2013-107)
Mozilla security developer Daniel Veditz discovered that restrictions are not applied to an element contained within a sandboxed iframe. This could allow content hosted within a sandboxed iframe to use element to bypass the sandbox restrictions that should be applied.
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-107.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Daniel Veditz as the original reporter.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2013:1812 https://rhn.redhat.com/errata/RHSA-2013-1812.h
Bugzilla
CVE-2013-5618 Mozilla: Use-after-free during Table Editing (MFSA 2013-109)
bugzilla·2013-12-09·CVSS 9.8
CVE-2013-5618 [CRITICAL] CVE-2013-5618 Mozilla: Use-after-free during Table Editing (MFSA 2013-109)
CVE-2013-5618 Mozilla: Use-after-free during Table Editing (MFSA 2013-109)
Security researcher Nils used the Address Sanitizer tool while fuzzing to discover a use-after-free problem in the table editing user interface of the editor during garbage collection. This leads to a potentially exploitable crash.
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-109.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Nils as the original reporter.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2013:1812 https://rhn.redhat.com/errata/RHSA-2013-1812.html
---
This issue has been addressed in following products:
Red H
Bugzilla
CVE-2013-1812 ruby-openid: Vulnerable to XIE DoS attacks [fedora-all]
bugzilla·2013-03-05·CVSS 4.3
CVE-2013-1812 [MEDIUM] CVE-2013-1812 ruby-openid: Vulnerable to XIE DoS attacks [fedora-all]
CVE-2013-1812 ruby-openid: Vulnerable to XIE DoS attacks [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mul
Bugzilla
CVE-2013-1812 ruby-openid: Vulnerable to XIE DoS attacks
bugzilla·2013-03-05·CVSS 4.3
CVE-2013-1812 [MEDIUM] CVE-2013-1812 ruby-openid: Vulnerable to XIE DoS attacks
CVE-2013-1812 ruby-openid: Vulnerable to XIE DoS attacks
A denial of service flaw was found in the way ruby-openid, a library for verifying and serving OpenID identities, performed processing of certain XML files. An OpenID provider could provide a specially-crafted XML file that, when processed would lead to excessive CPU consumption (denial of service).
References:
[1] https://github.com/openid/ruby-openid/pull/43
[2] https://bugzilla.novell.com/show_bug.cgi?id=804717
[3] http://www.openwall.com/lists/oss-security/2013/03/01/5
[4] http://www.openwall.com/lists/oss-security/2013/03/03/8
Relevant upstream patch:
[5] https://github.com/openid/ruby-openid/commit/a3693cef06049563f5b4e4824f4d3211288508ed
Discussion:
This issue affects the versions of the ruby-openid package, as shipped wi
Bugzilla
CVE-2013-0772 Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
bugzilla·2013-02-16·CVSS 5.8
CVE-2013-0772 [MEDIUM] CVE-2013-0772 Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
CVE-2013-0772 Mozilla: Out-of-bounds read in image rendering (MFSA 2013-22)
Using the Address Sanitizer tool, security researcher Atte Kettunen from OUSPG found an out-of-bounds read while rendering GIF format images. This could cause a non-exploitable crash and could also attempt to render normally inaccesible data as part of the image.
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-22.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Atte Kettunen as the original reporter.
Discussion:
Statement:
This issue has been addressed in firefox 24.2.0-ESR and thunderbird 24.2.0-ESR via RHSA-2013:1812 and RHSA-2013:1823.
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120204.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-November/120361.htmlhttp://www.openwall.com/lists/oss-security/2013/03/03/8https://bugzilla.redhat.com/show_bug.cgi?id=918134https://github.com/openid/ruby-openid/blob/master/CHANGELOG.mdhttps://github.com/openid/ruby-openid/commit/a3693cef06049563f5b4e4824f4d3211288508edhttps://github.com/openid/ruby-openid/pull/43http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120204.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-November/120361.htmlhttp://www.openwall.com/lists/oss-security/2013/03/03/8https://bugzilla.redhat.com/show_bug.cgi?id=918134https://github.com/openid/ruby-openid/blob/master/CHANGELOG.mdhttps://github.com/openid/ruby-openid/commit/a3693cef06049563f5b4e4824f4d3211288508edhttps://github.com/openid/ruby-openid/pull/43
2013-12-12
Published