[Japanese]

JVNDB-2004-000473

Ruby cgi.rb Denial of Service Vulnerability

Overview

Ruby cgi.rb enters an infinite loop which leads it into Ddenial of Service (DoS) due to improper input validation.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 5.0 (Medium) [NVD Score]
  • Access Vector: Network
  • Access Complexity: Low
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: None
  • Availability Impact: Partial
Affected Products


Ruby
  • Ruby 1.6.7 and earlier
  • Ruby 1.8.1 and earlier
Cybertrust Japan Co., Ltd.
  • Asianux Server 3.0
Turbolinux, Inc.
  • Turbolinux 10_f
  • Turbolinux Desktop 10
  • Turbolinux Server 10
  • Turbolinux Server 7
  • Turbolinux Server 8
  • Turbolinux Workstation 7
  • Turbolinux Workstation 8
  • Turbolinux Home
Red Hat, Inc.
  • Red Hat Enterprise Linux 2.1 (as)
  • Red Hat Enterprise Linux 3 (as)
  • Red Hat Enterprise Linux 2.1 (es)
  • Red Hat Enterprise Linux 3 (es)
  • Red Hat Enterprise Linux 2.1 (ws)
  • Red Hat Enterprise Linux 3 (ws)
  • Red Hat Enterprise Linux Desktop 3.0

Impact

An attacker could cause a Denial of Service (DoS) onto the systems.
Solution

Please refer to the 'Vendor Information' section for official remediation and take appropriate action.
Vendor Information

Ruby Cybertrust Japan Co., Ltd.
  • MIRACLE LINUX Update Information : ruby (V3.0) (Japanese)
Turbolinux, Inc. Red Hat, Inc.
CWE (What is CWE?)

CVE (What is CVE?)

  1. CVE-2004-0983
References

  1. National Vulnerability Database (NVD) : CVE-2004-0983
  2. Secunia Advisory : SA13123
  3. SecurityFocus : 11618
  4. ISS X-Force Database : 17985
  5. SecurityTracker : 1012120
Revision History

  • [2008/05/21]
      Web page published