Description
The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string.
Remediation
References
Related Vulnerabilities
WordPress Plugin Events Manager Pro CSV Injection (2.6.7.1)
markdown-it Improper Access Control Vulnerability (CVE-2015-3295)
WordPress Plugin Qyrr-simply and modern QR-Code creation Cross-Site Scripting (0.6)
Apache Tomcat Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-12617)