Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Translate 2024-08-01 DoS Rexml CVE news (zh_tw) #3335

Merged
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions zh_tw/news/_posts/2024-08-01-dos-rexml-cve-2024-41123.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
layout: news_post
title: "CVE-2024-41123: DoS vulnerabilities in REXML"
author: "kou"
translator: "Bear Su"
date: 2024-08-01 03:00:00 +0000
tags: security
lang: zh_tw
---

在 REXML gem 發現了一些 DoS 漏洞。
該漏洞的 CVE 編號為 [CVE-2024-41123](https://www.cve.org/CVERecord?id=CVE-2024-41123)。
我們強烈建議您升級 REXML gem。

## 風險細節

當解析包含許多特定字元如空白字元、`>]`、和 `]>` 的 XML 文件時,REXML gem 可能會需要很長的處理時間。

請更新 REXML gem 至 3.3.3 或更新的版本。

## 受影響版本

* REXML gem 3.3.2 及更早版本

## 致謝

感謝 [mprogrammer](https://hackerone.com/mprogrammer) 和 [scyoon](https://hackerone.com/scyoon) 發現這些問題。

## 歷史

* 最初發布於 2024-08-01 03:00:00 (UTC)
31 changes: 31 additions & 0 deletions zh_tw/news/_posts/2024-08-01-dos-rexml-cve-2024-41946.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
layout: news_post
title: "CVE-2024-41946: DoS vulnerability in REXML"
author: "kou"
translator: "Bear Su"
date: 2024-08-01 03:00:00 +0000
tags: security
lang: zh_tw
---

在 REXML gem 發現了一個 DoS 漏洞。
該漏洞的 CVE 編號為 [CVE-2024-41946](https://www.cve.org/CVERecord?id=CVE-2024-41946)。
我們強烈建議您升級 REXML gem。

## 風險細節

當使用 SAX2 或是 pull parser API 解析包含許多 entity expansion 的 XML 時,REXML gem 可能會需要很長的處理時間。

請更新 REXML gem 至 3.3.3 或更新的版本。

## 受影響版本

* REXML gem 3.3.2 及更早版本

## 致謝

感謝 [NAITOH Jun](https://github.com/naitoh) 發現並修復此問題。

## 歷史

* 最初發布於 2024-08-01 03:00:00 (UTC)