CVE-2024-49761: ReDoS vulnerability in REXML

There is a ReDoS vulnerability in REXML gem. This vulnerability has been assigned the CVE identifier CVE-2024-49761. We strongly recommend upgrading the REXML gem.

This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03.

Details

When parsing an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;).

Please update REXML gem to version 3.3.9 or later.

Affected versions

  • REXML gem 3.3.8 or prior with Ruby 3.1 or prior

Credits

Thanks to manun for discovering this issue.

History

  • Originally published at 2024-10-28 03:00:00 (UTC)

Posted by kou on 28 Oct 2024

What’s new in POSIX 2024 – XCU

As of the previous release of POSIX, the Austin Group gained more control over the specification, having it be more working group oriented, and they got to work making the POSIX specification more modern. POSIX 2024 is the first release that bears the fruits of this labor, and as such, the changes made to it are particularly interesting, as they will define the direction of the specification going forwards. This is what this article is about! Well, mostly. POSIX is composed of a couple of sections. Notably XBD (Base Definitions, which talk about things like what a file is, how regular expressions work, etc), XSH (System Interfaces, the C API that defines POSIX’s internals), and XCU (which defines the shell command language, and the standard utilities available for the system). There’s also XRAT, which explains the rationale of the authors, but it’s less relevant for our purposes today. XBD and XRAT are both interesting as context for XSH and XCU, but those are the real meat of the specification. This article will focus on the XCU section, in particular the utilities part of that section. If you’re more interested in the XSH section, there’s an excellent summary page by sortix’s Jonas Termansen that you can read here. ↫ im tosti The weekend isn’t over yet, so here’s some more light reading.

Bonanza 3×34 – El Creador De Milagros

Video by via Dailymotion Source Serie de TV (1959-1973). Temporada 03, 34 Capitulos, Ambientado en el Viejo Oeste americano (1860-1870). Todos los caminos pasan por La Ponderosa, el rancho de los Cartwight, que se encuentra en los alrededores de Virginia City, junto al Lago Tahoe (Nevada). Ben Cartwright es un viudo que cuida de sus … Read more

عرض إسرائيلي لحماس بعد السنوار

Video by via Dailymotion Source عرض إسرائيلي لحماس بعد السنوار العين الإخبارية.. بوابة إخبارية عربية شاملة، تغطي أخبار العالم العربي والدولي .. تضعك دائما في قلب الحدث، لتصبح عينك على العالم برؤية مختلفة، ومحتوى متميز———————————————–‎زوروا مواقعنا الخاصة #العين_الإخباريةWebsite: https://al-ain.comX: https://x.com/AlAinNewsTikTok: https://www.tiktok.com/@alainnewsYouTube: https://www.youtube.com/c/AlAinNewsFacebook: https://www.facebook.com/AlAinNewsInstagram: https://www.instagram.com/AlAinNewsLive Stream: https://www.youtube.com/c/AlAinNews/liveDailymotion: https://www.dailymotion.com/AlAinNewsThreads: https://www.threads.net/@alainnewsPeriscope: https://www.pscp.tv/alain_4uTelegram: https://telegram.me/alain4uApple Store: https://apple.co/3HT5QfrGoogle Play: https://bit.ly/3sWNpSQ Go … Read more

Tema Debat Kedua soal Ekonomi dan Kesejahteraan, Ketua Timses Ungkap Program Unggulan RK-Suswono

Video by via Dailymotion Source JAKARTA, KOMPAS.TV – Komisi Pemilihan Umum Provinsi Jakarta kembali menyelenggarakan Debat Calon Gubernur dan Wakil Gubernur Jakarta hari ini (27/10). Ini merupakan debat kedua yang dijalani para kandidat calon pemimpin Jakarta. Debat kedua ini digelar di Beach City International Stadium, Ancol, Jakarta Utara dengan tema ekonomi dan kesejahteraan sosial. Ketua … Read more

Mukaab – Saudi Arabia Begins Construction of World’s Largest Building

Video by via Dailymotion Source #MegaProjects #Architecture #MukaabSaudi Arabia begins construction work on its cube shaped skyscraper big enough to fit 20 Empire State Buildings. Mukaab will be 400 meters on each side when construction is finished making it the largest built structure in the world. The building will be the centerpiece of New Murabba, … Read more

Como foram os testes de integridade no Brasil? Secretário de auditoria do TRE-SP comenta

Video by via Dailymotion Source Marcos Miotto, secretário de auditoria do Tribunal Regional Eleitoral de São Paulo, concedeu entrevista ao Jornal da Manhã e falou sobre os testes de integridades das urnas eletrônicas em cidades que participam do segundo turno. Baixe o app Panflix: https://www.panflix.com.br/ Inscreva-se no nosso canal:https://www.youtube.com/c/jovempannews Siga o canal “Jovem Pan News” … Read more