Ruby OpenID: Denial of service A vulnerability in Ruby OpenID may lead to Denial of Service. ruby-openid 2014-05-17 2014-05-17 460156 remote 2.2.2 2.2.2

Ruby OpenID is a robust library for verifying and serving OpenID identities.

An XML entity parsing error has been discovered in Ruby OpenID.

A remote attacker could send a specially crafted XML file, possibly resulting in a Denial of Service condition.

There is no known workaround at this time.

All Ruby OpenID users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-ruby/ruby-openid-2.2.2"
CVE-2013-1812 ackle ackle