7.8
CVSSv2

CVE-2008-4310

Published: 09/12/2008 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote malicious users to cause a denial of service (CPU consumption) via a crafted HTTP request. NOTE: this issue exists because of an incomplete fix for CVE-2008-3656.

Vulnerable Product Search on Vulmon Subscribe to Product

ruby-lang ruby 1.8.5

ruby-lang ruby 1.8.1

Vendor Advisories

Synopsis Moderate: ruby security update Type/Severity Security Advisory: Moderate Topic Updated ruby packages that fix a security issue are now available for RedHat Enterprise Linux 4 and 5This update has been rated as having moderate security impact by the RedHat Security Response Team Descripti ...

Exploits

source: wwwsecurityfocuscom/bid/30644/info Ruby is prone to multiple vulnerabilities that can be leveraged to bypass security restrictions or cause a denial of service: - Multiple security-bypass vulnerabilities occur because of errors in the 'safe level' restriction implementation Attackers can leverage these issues to make insecure fu ...