VDB
Sign up
HIGH7.5

GHSA-v6rp-3r3v-hf4p

Ruby OpenSSL DoS Vulnerability

Quick fix

GHSA-v6rp-3r3v-hf4p — openssl: upgrade to the fixed version with the command below.

bundle update openssl

Details

The decode method in the `OpenSSL::ASN1` module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string. The `openssl` gem that contains this module is patched in version 2.0.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/openssl
Introduced in: 0Fixed in: 2.0.0
Fixbundle update openssl

References