SB2017110324 - Fedora EPEL 7 update for rubygem-ox
Published: November 3, 2017 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2017-15928)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.
Remediation
Install update from vendor's website.