CVE-2013-1812: XEE

Published Mar 5, 2013
·
Updated

A denial of service flaw was found in the way ruby-openid, a library for verifying and serving OpenID identities, performed processing of certain XML files. An OpenID provider could provide a specially-crafted XML file that, when processed would lead to excessive CPU consumption (denial of service).

References: [1] https://github.com/openid/ruby-openid/pull/43 [2] https://bugzilla.novell.com/showbug.cgi?id=804717 [3] http://www.openwall.com/lists/oss-security/2013/03/01/5 [4] http://www.openwall.com/lists/oss-security/2013/03/03/8

Relevant upstream patch: [5] https://github.com/openid/ruby-openid/commit/a3693cef06049563f5b4e4824f4d3211288508ed

Other sources

The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.

Affected Software

5 affected componentsFixes available
rubygems/ruby-openid<2.2.2
2.2.2
Fedoraproject Fedora=17
Fedoraproject Fedora=18
Janrain Ruby-openid Ruby<=2.2.1
Janrain Ruby-openid Ruby=2.2.0

Event History

Mar 5, 2013
Data Sourced
02:59 PM
DescriptionSeverityAffected Software
Dec 12, 2013
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Oct 24, 2017
Advisory Published
06:33 PM

Frequently Asked Questions

1

What is the severity of CVE-2013-1812?

CVE-2013-1812 is classified as a denial of service vulnerability due to excessive CPU consumption.

2

How do I fix CVE-2013-1812?

To fix CVE-2013-1812, upgrade ruby-openid to version 2.2.2 or later.

3

What systems are affected by CVE-2013-1812?

CVE-2013-1812 affects ruby-openid versions up to and including 2.2.1, along with specific Fedora releases 17 and 18.

4

What impact does CVE-2013-1812 have on my application?

CVE-2013-1812 can lead to a denial of service, causing application downtime due to high CPU usage.

5

Is there a known exploit for CVE-2013-1812?

Yes, CVE-2013-1812 can be exploited when an OpenID provider sends a specially-crafted XML file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203