CVE-2014-8080: XEE
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8080?
CVE-2014-8080 is classified as a denial of service vulnerability due to potential memory consumption.
How do I fix CVE-2014-8080?
To fix CVE-2014-8080, upgrade Ruby to version 1.9.3-p550 or higher, 2.0.0-p594 or higher, or 2.1.4 or higher.
What type of attack does CVE-2014-8080 allow?
CVE-2014-8080 allows attackers to execute an XML Entity Expansion (XEE) attack.
Which versions of Ruby are affected by CVE-2014-8080?
CVE-2014-8080 affects Ruby versions 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4.
Which operating systems are vulnerable to CVE-2014-8080?
CVE-2014-8080 affects various Linux distributions, including specific versions of openSUSE, Ubuntu, and Red Hat Enterprise Linux.