[Japanese]

JVNDB-2006-000808

Denial of service vulnerability in Ruby CGI library (cgi.rb)

Overview

cgi.rb, a standard library in Ruby, contains a denial of service vulnerability.

This vulnerability is different from CVE-2006-5467.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 5.0 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Low
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: None
  • Availability Impact: Partial
Affected Products


Ruby
  • Ruby 1.8.5 and all previous versions
  • Ruby Developer version (1.9 series) 2006-12-04 and all previous versions
Turbolinux, Inc.
  • Turbolinux 10_f
  • Turbolinux Appliance Server 2.0
  • Turbolinux Desktop 10
  • Turbolinux FUJI
  • Turbolinux Multimedia
  • Turbolinux Personal
  • Turbolinux Server 10
  • Turbolinux Server 10 (x64)
  • Turbolinux Server 8
  • Turbolinux Home
MIRACLE LINUX CORPORATION
  • Asianux Server 3.0
  • Asianux Server 3.0 (x86-64)
Red Hat, Inc.
  • Red Hat Enterprise Linux 4 (as)
  • Red Hat Enterprise Linux 4 (es)
  • Red Hat Enterprise Linux 4 (ws)
  • Red Hat Enterprise Linux 2.1 (as)
  • Red Hat Enterprise Linux 3 (as)
  • Red Hat Enterprise Linux 2.1 (es)
  • Red Hat Enterprise Linux 3 (es)
  • Red Hat Enterprise Linux 2.1 (ws)
  • Red Hat Enterprise Linux 3 (ws)
  • Red Hat Enterprise Linux Desktop 4.0
  • Red Hat Enterprise Linux Desktop 3.0

Impact

A remote attacker could possibly conduct a DoS attack on a Ruby server by sending it a specially crafted request.
Solution

Vendor Information

Ruby Turbolinux, Inc. MIRACLE LINUX CORPORATION
  • MIRACLE LINUX Update Information : 1336 (Japanese)
Red Hat, Inc.
CWE (What is CWE?)

  1. Resource Management Errors(CWE-399) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2006-6303
References

  1. JVN : JVN#84798830
  2. National Vulnerability Database (NVD) : CVE-2006-6303
  3. Secunia Advisory : SA13123
  4. SecurityFocus : 21441
  5. ISS X-Force Database : 30734
  6. SecurityTracker : 1017363
  7. FrSIRT Advisories : FrSIRT/ADV-2006-4855
  8. JVN iPedia (Japanese) : JVNDB-2006-000808
Revision History

  • [2008/05/21]
      Web page published
    [2008/07/30]
      Affected Products : Red Hat, Inc. (RHSA-2008:0562).
      Vendor Information : Red Hat, Inc. (RHSA-2008:0562).
    [2008/11/14]
      Affected Products : MIRACLE LINUX CORPORATION (1336).
      Vendor Information : MIRACLE LINUX CORPORATION (1336).