>> Ruby REXML Library Entities Handling Denial of Service Vulnerability
Title : Ruby REXML Library Entities Handling Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-2428 CVE ID : CVE-2008-3790 CWE ID : CWE-400
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-25
Technical Description
A vulnerability has been identified in Ruby, which could be exploited by attackers to cause a denial of service. This issue is caused by an error in the REXML library when parse an XML document containing recursively nested entities, which could be exploited to create a denial of service condition via a malicious XML file.