CVE-2015-3227
medium
CVSS v3
—
CVSS v2
5.0
VIR risk
5.0
Description
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-3227
Vendor advisory: secalert@redhat.com — https://groups.google.com/forum/message/raw?msg=rubyonrails-security/bahr2JLnxvk/x4EocXnHPp8J
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| suse | 13.1 | affected | |
| suse | 13.2 | affected | |
| debian | bookworm | fixed | 2:4.2.4-2 |
| debian | bullseye | fixed | 2:4.2.4-2 |
| debian | forky | fixed | 2:4.2.4-2 |
| debian | sid | fixed | 2:4.2.4-2 |
| debian | trixie | fixed | 2:4.2.4-2 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| RubyGems | activesupport | <>= 4.2.2 | >= 4.2.2 |
| RubyGems | activesupport | >=4.0.0.beta1,<4.1.11 | 4.1.11 |
| RubyGems | activesupport | >=4.2.0.beta1,<4.2.2 | 4.2.2 |
| RubyGems | activesupport | <3.2.22 | 3.2.22 |
References
- https://groups.google.com/forum/#!topic/rubyonrails-security/bahr2JLnxvk
- http://lists.opensuse.org/opensuse-updates/2015-07/msg00050.html
- http://openwall.com/lists/oss-security/2015/06/16/16
- http://www.debian.org/security/2016/dsa-3464
- http://www.securityfocus.com/bid/75234
- http://www.securitytracker.com/id/1033755
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/bahr2JLnxvk/x4EocXnHPp8J
- https://nvd.nist.gov/vuln/detail/CVE-2015-3227
- https://github.com/rails/rails/commit/12f763ce1131d29d24bd0d8f868e2697a139aea3
- https://github.com/rails/rails/commit/153cc843ad95930b00b0ca91d30b599b7dec9680
- https://github.com/rails/rails/commit/78b29e08c700d889837af6c51c7debd3864abc3d
- https://github.com/rails/rails
- https://web.archive.org/web/20200228041703/http://www.securityfocus.com/bid/75234
- https://web.archive.org/web/20200517005133/http://www.securitytracker.com/id/1033755
- https://security-tracker.debian.org/tracker/CVE-2015-3227
Verify integrity in audit chain (admin only). AS-IS.