Advisory Database
  • Advisories
  • Dependency Scanning
  1. gem
  2. ›
  3. enum_column3
  4. ›
  5. OSVDB-94679

OSVDB-94679: Symbol Creation Remote DoS

June 26, 2013

The package enum_column3 for Ruby contains a flaw that may allow a remote denial of service. The issue is due to the program typecasting unexpected strings to symbols. This may allow a remote attacker to crash the program.

References

  • github.com/electronick/enum_column/pull/21

Code Behaviors & Features

Detect and mitigate OSVDB-94679 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 0.1.4

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, a patch has been committed to the source code repository that addresses this vulnerability. Until it is incorporated into the next release of the software, manually patching an existing installation is the only known available solution. Check thttps://github.com/HonoreDB/enum_column/commit/a08246f3db804eac1807ec15e59e0ebdc2ec5c90 for more information.

Source file

gem/enum_column3/OSVDB-94679.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:26 +0000.