<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 22:59:54 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0298 — De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0298</link>
      <description>certfr-2025-avi-0298</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0298</guid>
    </item>
    <item>
      <title>EUVD-2026-161043</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-161043</link>
      <description>EUVD-2026-161043</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-161043</guid>
    </item>
    <item>
      <title>fkie_cve-2024-43380</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-43380</link>
      <description>&lt;p&gt;fugit contains time tools for flor and the floraison group. The fugit &amp;#34;natural&amp;#34; parser, that turns &amp;#34;every wednesday at 5pm&amp;#34; into &amp;#34;0 17 * * 3&amp;#34;, accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fugit contains time tools for flor and the floraison group. The fugit &amp;#34;natural&amp;#34; parser, that turns &amp;#34;every wednesday at 5pm&amp;#34; into &amp;#34;0 17 * * 3&amp;#34;, accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-43380</guid>
    </item>
    <item>
      <title>GHSA-2m96-52r3-2f3g — fugit parse and parse_nat stall on lengthy input</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2m96-52r3-2f3g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: fugit&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The fugit &amp;#34;natural&amp;#34; parser, that turns &amp;#34;every wednesday at 5pm&amp;#34; into &amp;#34;0 17 * * 3&amp;#34;, accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight.&lt;/p&gt;
&lt;p&gt;Fugit dependents that do not check (user) input length for plausability are impacted.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Problem was reported in #104 and the fix was released in [fugit 1.11.1](https://rubygems.org/gems/fugit/versions/1.11.1)&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;By making sure that `Fugit.parse(s)`, `Fugit.do_parse(s)`, `Fugit.parse_nat(s)`, `Fugit.do_parse_nat(s)`, `Fugit::Nat.parse(s)`, and `Fugit::Nat.do_parse(s)` are not fed strings too long. 1000 chars feels ok, while 10_000 chars makes it stall.&lt;/p&gt;
&lt;p&gt;In fewer words, making sure those fugit methods are not fed unvetted input strings.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;gh-104&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: fugit&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The fugit &amp;#34;natural&amp;#34; parser, that turns &amp;#34;every wednesday at 5pm&amp;#34; into &amp;#34;0 17 * * 3&amp;#34;, accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight.&lt;/p&gt;
&lt;p&gt;Fugit dependents that do not check (user) input length for plausability are impacted.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Problem was reported in #104 and the fix was released in [fugit 1.11.1](https://rubygems.org/gems/fugit/versions/1.11.1)&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;By making sure that `Fugit.parse(s)`, `Fugit.do_parse(s)`, `Fugit.parse_nat(s)`, `Fugit.do_parse_nat(s)`, `Fugit::Nat.parse(s)`, and `Fugit::Nat.do_parse(s)` are not fed strings too long. 1000 chars feels ok, while 10_000 chars makes it stall.&lt;/p&gt;
&lt;p&gt;In fewer words, making sure those fugit methods are not fed unvetted input strings.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;gh-104&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2m96-52r3-2f3g</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-43380</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-43380</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: ruby-fugit, Ubuntu:22.04:LTS: ruby-fugit, Ubuntu:24.04:LTS: ruby-fugit&lt;/p&gt;
&lt;p&gt;fugit contains time tools for flor and the floraison group. The fugit &amp;#34;natural&amp;#34; parser, that turns &amp;#34;every wednesday at 5pm&amp;#34; into &amp;#34;0 17 * * 3&amp;#34;, accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: ruby-fugit, Ubuntu:22.04:LTS: ruby-fugit, Ubuntu:24.04:LTS: ruby-fugit&lt;/p&gt;
&lt;p&gt;fugit contains time tools for flor and the floraison group. The fugit &amp;#34;natural&amp;#34; parser, that turns &amp;#34;every wednesday at 5pm&amp;#34; into &amp;#34;0 17 * * 3&amp;#34;, accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-43380</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-2159 — IBM License Metric Tool: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2159</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2159</guid>
    </item>
  </channel>
</rss>
