Candidate: CVE-2015-4410 PublicDate: 2020-02-20 17:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4410 http://sakurity.com/blog/2015/06/04/mongo_ruby_regexp.html https://sources.debian.net/src/ruby-bson/1.10.0-1/lib/bson/types/object_id.rb/#L54 http://www.openwall.com/lists/oss-security/2015/06/06/1 Description: The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=787951 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_ruby-bson: upstream_ruby-bson: released (1.10.0-2, 1.10.0-1+deb8u1) precise_ruby-bson: DNE precise/esm_ruby-bson: DNE trusty_ruby-bson: ignored (reached end-of-life) trusty/esm_ruby-bson: DNE (trusty was needed) utopic_ruby-bson: ignored (reached end-of-life) vivid_ruby-bson: ignored (reached end-of-life) vivid/stable-phone-overlay_ruby-bson: DNE vivid/ubuntu-core_ruby-bson: DNE wily_ruby-bson: ignored (reached end-of-life) xenial_ruby-bson: not-affected (1.10.0-2) yakkety_ruby-bson: ignored (reached end-of-life) zesty_ruby-bson: ignored (reached end-of-life) artful_ruby-bson: ignored (reached end-of-life) bionic_ruby-bson: not-affected (1.10.0-2) cosmic_ruby-bson: not-affected (1.10.0-2) disco_ruby-bson: not-affected (1.10.0-2) devel_ruby-bson: not-affected (1.10.0-2)