REDHAT-BUG-918134: Low severity Openid ruby-openid vulnerability
A denial of service flaw was found in the way ruby-openid, a library for verifying and serving OpenID identities, performed processing of certain XML files. An OpenID provider could provide a specially-crafted XML file that, when processed would lead to excessive CPU consumption (denial of service).
References: [1] https://github.com/openid/ruby-openid/pull/43 [2] https://bugzilla.novell.com/showbug.cgi?id=804717 [3] http://www.openwall.com/lists/oss-security/2013/03/01/5 [4] http://www.openwall.com/lists/oss-security/2013/03/03/8
Relevant upstream patch: [5] https://github.com/openid/ruby-openid/commit/a3693cef06049563f5b4e4824f4d3211288508ed
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-918134?
The severity of REDHAT-BUG-918134 is classified as a denial of service vulnerability due to excessive CPU consumption.
How do I fix REDHAT-BUG-918134?
To fix REDHAT-BUG-918134, ensure that you are using the latest version of the ruby-openid library that addresses this flaw.
What software is affected by REDHAT-BUG-918134?
REDHAT-BUG-918134 affects the ruby-openid library utilized for verifying OpenID identities.
Is there a risk of exploitation with REDHAT-BUG-918134?
Yes, REDHAT-BUG-918134 presents a risk as it allows an OpenID provider to submit a malicious XML file that could lead to denial of service.
When was REDHAT-BUG-918134 reported?
REDHAT-BUG-918134 was reported in 2013, indicating a long-standing vulnerability that requires attention.