CVE-2014-8080
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/11/2014
Last modified:
12/04/2025
Description
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ruby-lang:ruby:*:p550:*:*:*:*:*:* | 1.9.3 (including) | |
| cpe:2.3:a:ruby-lang:ruby:1.9.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ruby-lang:ruby:1.9.3:p0:*:*:*:*:*:* | ||
| cpe:2.3:a:ruby-lang:ruby:1.9.3:p125:*:*:*:*:*:* | ||
| cpe:2.3:a:ruby-lang:ruby:1.9.3:p194:*:*:*:*:*:* | ||
| cpe:2.3:a:ruby-lang:ruby:1.9.3:p286:*:*:*:*:*:* | ||
| cpe:2.3:a:ruby-lang:ruby:1.9.3:p383:*:*:*:*:*:* | ||
| cpe:2.3:a:ruby-lang:ruby:1.9.3:p385:*:*:*:*:*:* | ||
| cpe:2.3:a:ruby-lang:ruby:1.9.3:p392:*:*:*:*:*:* | ||
| cpe:2.3:a:ruby-lang:ruby:1.9.3:p426:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://advisories.mageia.org/MGASA-2014-0443.html
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
- http://lists.opensuse.org/opensuse-updates/2014-12/msg00035.html
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00004.html
- http://rhn.redhat.com/errata/RHSA-2014-1911.html
- http://rhn.redhat.com/errata/RHSA-2014-1912.html
- http://rhn.redhat.com/errata/RHSA-2014-1913.html
- http://rhn.redhat.com/errata/RHSA-2014-1914.html
- http://secunia.com/advisories/61607
- http://secunia.com/advisories/62050
- http://secunia.com/advisories/62748
- http://www.debian.org/security/2015/dsa-3157
- http://www.debian.org/security/2015/dsa-3159
- http://www.mandriva.com/security/advisories?name=MDVSA-2015%3A129
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.securityfocus.com/bid/70935
- http://www.ubuntu.com/usn/USN-2397-1
- https://support.apple.com/HT205267
- https://www.ruby-lang.org/en/news/2014/10/27/rexml-dos-cve-2014-8080/
- http://advisories.mageia.org/MGASA-2014-0443.html
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
- http://lists.opensuse.org/opensuse-updates/2014-12/msg00035.html
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00004.html
- http://rhn.redhat.com/errata/RHSA-2014-1911.html
- http://rhn.redhat.com/errata/RHSA-2014-1912.html
- http://rhn.redhat.com/errata/RHSA-2014-1913.html
- http://rhn.redhat.com/errata/RHSA-2014-1914.html
- http://secunia.com/advisories/61607
- http://secunia.com/advisories/62050
- http://secunia.com/advisories/62748
- http://www.debian.org/security/2015/dsa-3157
- http://www.debian.org/security/2015/dsa-3159
- http://www.mandriva.com/security/advisories?name=MDVSA-2015%3A129
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.securityfocus.com/bid/70935
- http://www.ubuntu.com/usn/USN-2397-1
- https://support.apple.com/HT205267
- https://www.ruby-lang.org/en/news/2014/10/27/rexml-dos-cve-2014-8080/



