CVE-2014-10077
published 2018-11-06CVE-2014-10077: Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a…
PriorityP431high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.39%
87.6th percentile
Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ruby-i18n | < ruby-i18n 0.7.0-3 (bookworm) | ruby-i18n 0.7.0-3 (bookworm) |
| i18n_project | i18n | < 0.8.0 | 0.8.0 |
| i18n_project | i18n | >= 0 < 0.8.0 | 0.8.0 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
i18n Vulnerable to Denial of Service Attack
ghsa·2022-05-14
CVE-2014-10077 [HIGH] CWE-20 i18n Vulnerable to Denial of Service Attack
i18n Vulnerable to Denial of Service Attack
Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.
OSV
i18n Vulnerable to Denial of Service Attack
osv·2022-05-14
CVE-2014-10077 [HIGH] i18n Vulnerable to Denial of Service Attack
i18n Vulnerable to Denial of Service Attack
Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.
OSV
CVE-2014-10077: Hash#slice in lib/i18n/core_ext/hash
osv·2018-11-06·CVSS 7.5
CVE-2014-10077 [HIGH] CVE-2014-10077: Hash#slice in lib/i18n/core_ext/hash
Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.
Red Hat
rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb
vendor_redhat·2015-07-20·CVSS 7.5
CVE-2014-10077 [HIGH] CWE-400 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb
rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb
Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.
Statement: Red Hat Satellite 6.2 is now in Maintenance support 2 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Satellite Product Life Cycle: https://access.redhat.com/support/policy/updates/satellite
Red Hat Satellite 6.3 and 6.4 don't include vulnerable package tfm-rubygem-i18n, hence are not affected by this flaw.
Subscription Asset Manager is now in
Debian
CVE-2014-10077: ruby-i18n - Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby al...
vendor_debian·2014·CVSS 7.5
CVE-2014-10077 [HIGH] CVE-2014-10077: ruby-i18n - Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby al...
Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.
Scope: local
bookworm: resolved (fixed in 0.7.0-3)
bullseye: resolved (fixed in 0.7.0-3)
forky: resolved (fixed in 0.7.0-3)
sid: resolved (fixed in 0.7.0-3)
trixie: resolved (fixed in 0.7.0-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-10077 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb [fedora-all]
bugzilla·2018-11-07·CVSS 7.5
CVE-2014-10077 [HIGH] CVE-2014-10077 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb [fedora-all]
CVE-2014-10077 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2014-10077 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb [epel-7]
bugzilla·2018-11-07·CVSS 7.5
CVE-2014-10077 [HIGH] CVE-2014-10077 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb [epel-7]
CVE-2014-10077 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following temp
Bugzilla
CVE-2014-10077 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb
bugzilla·2018-11-07·CVSS 7.5
CVE-2014-10077 [HIGH] CVE-2014-10077 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb
CVE-2014-10077 rubygem-i18n: denial of service in Hash#slice in lib/i18n/core_ext/hash.rb
A flaw was found in the i18n gem before 0.8.0 for Ruby. The Hash#slice in lib/i18n/core_ext/hash.rb allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.
References:
https://github.com/rubysec/ruby-advisory-db/pull/182/files
https://github.com/svenfuchs/i18n/pull/289
https://github.com/svenfuchs/i18n/releases/tag/v0.8.0
Discussion:
Created rubygem-i18n tracking bugs for this issue:
Affects: epel-7 [bug 1647433]
Affects: fedora-all [bug 1647432]
---
This issue affects the versions of rubygem-i18n shipped in the logging-fluentd and ose-logging-fluentd containers in OpenShift Containe
https://github.com/rubysec/ruby-advisory-db/pull/182/fileshttps://github.com/svenfuchs/i18n/pull/289https://github.com/svenfuchs/i18n/releases/tag/v0.8.0https://lists.debian.org/debian-lts-announce/2018/11/msg00021.htmlhttps://github.com/rubysec/ruby-advisory-db/pull/182/fileshttps://github.com/svenfuchs/i18n/pull/289https://github.com/svenfuchs/i18n/releases/tag/v0.8.0https://lists.debian.org/debian-lts-announce/2018/11/msg00021.html
2018-11-06
Published