Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200612-21] Ruby: Denial of Service vulnerability


Vulnerability Assessment Details

[GLSA-200612-21] Ruby: Denial of Service vulnerability

Vulnerability Assessment Summary
Ruby: Denial of Service vulnerability

Detailed Explanation for this Vulnerability Assessment
The remote host is affected by the vulnerability described in GLSA-200612-21
(Ruby: Denial of Service vulnerability)


The read_multipart function of the CGI library shipped with Ruby
(cgi.rb) does not properly check boundaries in MIME multipart content.
This is a different issue than GLSA 200611-12.

Impact

The vulnerability can be exploited by sending the cgi.rb library a
crafted HTTP request with multipart MIME encoding that contains a
malformed MIME boundary specifier. Successful exploitation of the
vulnerability causes the library to go into an infinite loop.

Workaround

There is no known workaround at this time.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6303


Solution:
All Ruby users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/ruby-1.8.5_p2"


Network Security Threat Level: Medium


Networks Security ID:

Vulnerability Assessment Copyright: (C) 2006 Michel Arboi

Cables, Connectors

DELL POWEREDGE R820 16 BAY TWO E5-4607V2 2.6GHZ 32GB 14 X 1.6TB SSD H310
$15929.0
DELL POWEREDGE R820 16 BAY TWO E5-4607V2 2.6GHZ 32GB 14 X 1.6TB SSD H310 pictureDELL POWEREDGE R820 16 BAY TWO E5-4620V2 2.6GHZ 48GB 10 X 600GB 10K SAS H710
$5399.0
DELL POWEREDGE R820 16 BAY TWO E5-4620V2 2.6GHZ 48GB 10 X 600GB 10K SAS H710 pictureDELL POWEREDGE R820 SERVER 8B TWO E5-4657LV2 2.4GHZ 32GB 4 X 1.2TB 10K SAS H710P
$5749.0
DELL POWEREDGE R820 SERVER 8B TWO E5-4657LV2 2.4GHZ 32GB 4 X 1.2TB 10K SAS H710P pictureDELL POWEREDGE R630 10 BAY TWO E5-2643V4 3.4GHZ 192GB 10 X 1.2TB 10K 12G H330
$11499.0
DELL POWEREDGE R630 10 BAY TWO E5-2643V4 3.4GHZ 192GB 10 X 1.2TB 10K 12G H330 picture


Discussions

No Discussions have been posted on this vulnerability.