Logo
vulnerabilityCVE-2023-36617
Name
CVE-2023-36617
Source
NVD ( link)Debian ( link)
Description
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this issue exists becuse of an incomplete fix for CVE-2023-28755. Version 0.10.3 is also a fixed version.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ruby
Patched

Vulnerability Rating#


5.3
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.4.9
Not Affected
buildroot
master
4.0.3
Not Affected
openwrt
master
4.0.2-r1
Not Affected
openwrt
openwrt-25.12
3.4.9-r1
Not Affected
yocto
master
4.0.5
Not Affected
yocto
scarthgap
3.3.10
Not Affected

Resolved with patches#


ruby (yocto:kirkstone)

#
Title
Author
Resolve
1
ruby: Fix quadratic backtracking on invalid port number
Nobuyoshi Nakada <nobu@ruby-lang.org>
CVE-2023-36617
2
ruby: Fix quadratic backtracking on invalid relative URI
Nobuyoshi Nakada <nobu@ruby-lang.org>
CVE-2023-36617