CVE-2017-6181

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
03/04/2017
Last modified:
20/04/2025

Description

The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Ruby 2.4.0, allows remote attackers to cause a denial of service (deep recursion and application crash) via a crafted regular expression.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ruby-lang:ruby:2.4.0:*:*:*:*:*:*:*