CVE-2024-39908 and CVE-2024-41123 commit #232
Copy link
Copy link
Closed
Description
Activity
I already answered this:
- Add support for XML entity expansion limitation in SAX and pull parsers #187 (comment)
- 7cb5eae#commitcomment-150937839
What is needed for Debian?
@kou are you sure that
CVE-2024-39908 : When it parses an XML that has many specific characters such as <, 0 and %>. REXML gem may take long time.
CVE-2024-41123: When parsing an XML document that has many specific characters such as whitespace character, >] and ]>, REXML gem may take long time.Are fixed by a namespace fix ?
Ah, you referred different CVEs. Sorry.
FYI: They may depend on other commits. So it may be difficult to backport only them. Updating to 3.3.2 or 3.3.3 will be safe. (It doesn't introduce unrelated DoS/bug by wrong backport.)
Metadata
Metadata
Assignees
Labels
No labels
Hi,
On debian security side we need a statement about commit for this two CVEs
What are the commit fixing this ?
Thanks
Bastien