Ruby OpenID: Denial of service — GLSA 201405-14

A vulnerability in Ruby OpenID may lead to Denial of Service.

Affected packages

dev-ruby/ruby-openid on all architectures
Affected versions < 2.2.2
Unaffected versions >= 2.2.2

Background

Ruby OpenID is a robust library for verifying and serving OpenID identities.

Description

An XML entity parsing error has been discovered in Ruby OpenID.

Impact

A remote attacker could send a specially crafted XML file, possibly resulting in a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All Ruby OpenID users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-ruby/ruby-openid-2.2.2"
 

References

Release date
May 17, 2014

Latest revision
May 17, 2014: 1

Severity
normal

Exploitable
remote

Bugzilla entries