Input validation error in RubyGems and Ruby - CVE-2013-4363
Published: October 18, 2013 / Updated: August 10, 2020
RubyGems
Ruby
Detailed vulnerability description
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression.