Ruby Improper Input Validation Vulnerability - CVE-2008-3790 - Vulnerability Database

Ruby Improper Input Validation Vulnerability - CVE-2008-3790

Medium
Reference: CVE-2008-3790
Title: Ruby Improper Input Validation Vulnerability
Overview:

The REXML module in Ruby 1.8.6 through 1.8.6-p287 1.8.7 through 1.8.7-p72 and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities aka an quotXML entity explosion.quot