• 公告ID (KylinSec-SA-2023-1524)

摘要:

A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.

安全等级: Low

公告ID: KylinSec-SA-2023-1524

发布日期: 2023年7月10日

关联CVE: CVE-2023-36617  

  • 详细介绍

1. 漏洞描述

   

A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-36617 KY3.4-4A perl-URI Unaffected
CVE-2023-36617 KY3.4-5A perl-URI Unaffected
CVE-2023-36617 KY3.5.1 perl-URI Unaffected
CVE-2023-36617 KY3.5.2 perl-URI Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2023-1523 下一篇:KylinSec-SA-2023-1525