Ruby Resource Management Errors Vulnerability - CVE-2008-3443 - Vulnerability Database

Ruby Resource Management Errors Vulnerability - CVE-2008-3443

Medium
Reference: CVE-2008-3443
Title: Ruby Resource Management Errors Vulnerability
Overview:

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier 1.8.6 through 1.8.6-p286 1.8.7 through 1.8.7-p71 and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket related to memory allocation failure and as demonstrated against Webrick.