DEBIAN-CVE-2013-1812

Source
https://security-tracker.debian.org/tracker/CVE-2013-1812
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-1812.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2013-1812
Upstream
Published
2013-12-12T18:55:10.663Z
Modified
2025-11-19T01:19:10.627533Z
Summary
[none]
Details

The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.

References

Affected packages

Debian:11 / ruby-openid

Package

Name
ruby-openid
Purl
pkg:deb/debian/ruby-openid?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.8debian-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-1812.json"

Debian:12 / ruby-openid

Package

Name
ruby-openid
Purl
pkg:deb/debian/ruby-openid?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.8debian-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-1812.json"

Debian:13 / ruby-openid

Package

Name
ruby-openid
Purl
pkg:deb/debian/ruby-openid?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.8debian-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-1812.json"

Debian:14 / ruby-openid

Package

Name
ruby-openid
Purl
pkg:deb/debian/ruby-openid?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.8debian-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source

"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-1812.json"