VYPR

rpm package

opensuse/rubygem-websocket-extensions&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/rubygem-websocket-extensions&distro=openSUSE%20Tumbleweed

Vulnerabilities (1)

  • CVE-2020-7663Jun 2, 2020
    affected < 0.1.5-1.20fixed 0.1.5-1.20

    websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash an