VYPR

rpm package

suse/rubygem-websocket-extensions&distro=SUSE Linux Enterprise High Availability Extension 15 SP2

pkg:rpm/suse/rubygem-websocket-extensions&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP2

Vulnerabilities (1)

  • CVE-2020-7663Jun 2, 2020
    affected < 0.1.3-150000.3.4.1fixed 0.1.3-150000.3.4.1

    websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash an