5
CVSSv2

CVE-2004-0983

Published: 01/03/2005 Updated: 03/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The CGI module in Ruby 1.6 prior to 1.6.8, and 1.8 prior to 1.8.2, allows remote malicious users to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.

Vulnerable Product Search on Vulmon Subscribe to Product

yukihiro matsumoto ruby 1.8.2_pre2

yukihiro matsumoto ruby 1.6.7

yukihiro matsumoto ruby 1.8

yukihiro matsumoto ruby 1.6

yukihiro matsumoto ruby 1.8.1

yukihiro matsumoto ruby 1.8.2_pre1

mandrakesoft mandrake linux 9.2

mandrakesoft mandrake linux corporate server 2.1

mandrakesoft mandrake linux 10.0

mandrakesoft mandrake linux 10.1

ubuntu ubuntu linux 4.1

gentoo linux

Vendor Advisories

Synopsis ruby security update Type/Severity Security Advisory: Moderate Topic An updated ruby package that fixes a denial of service issue for the CGIinstance is now available[Updated 17 Jan 2005]Errata has been updated to include 32-bit libraries on 64-bit architectures Description Ruby ...
The Ruby developers discovered a potential Denial of Service vulnerability in the CGI module (cgirb) Specially crafted CGI requests could cause an infinite loop in the server process Repetitive attacks could use most of the available processor resources, exhaust the number of allowed parallel connections in web servers, or cause similar effects ...