Mageni can help you to save time and money
Mageni automates for you the vulnerability scanning, assessment and management process saving you a ton of time, resources, and money. Mageni is used by companies of all sizes. You will love Mageni's powerful features and ease of use. No registration or credit card is required.
Download Now
Debian LTS: Security Advisory for ruby-websocket-extensions (DLA-2334-1)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
The remote host is missing an update for the 'ruby-websocket-extensions' package(s) announced via the DLA-2334-1 advisory.
Insight
Insight
It was discovered that there was a denial of service vulnerability in ruby-websocket-extensions, a library for managing long-lived HTTP 'WebSocket' connections. The parser took quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence. This could be abused by an attacker to conduct a Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload in the Sec-WebSocket-Extensions HTTP header.
Affected Software
Affected Software
'ruby-websocket-extensions' package(s) on Debian Linux.
Detection Method
Detection Method
Checks if a vulnerable package version is present on the target host.
Solution
Solution
For Debian 9 'Stretch', this problem has been fixed in version 0.1.2-1+deb9u1. We recommend that you upgrade your ruby-websocket-extensions packages.
Common Vulnerabilities and Exposures (CVE)
References
Automate with a few clicks your vulnerability scanning, assessment and management process
Automate with a few clicks your vulnerability scanning, assessment and management process
Mageni automates for you the vulnerability scanning, assessment and management process saving you a ton of time, resources, and money. No registration or credit card is required. Mageni Community Edition is fast, powerful, free, and open-source. Download it now and Mageni will find your vulnerabilities before they are exploited by hackers.
1. Download Multipass
2. Launch a multipass instance
3. Install Mageni
1. If you don’t have it already, install Brew. Then, to install Multipass simply execute:
2. Launch a multipass instance
2. Install Mageni
1. Download the installer for Windows
2. Ensure your network is private
3. Run the installer
4. Launch a multipass instance
5. Log into the multipass instance
6. Install Mageni