Lucene search

K
freebsdFreeBSDAB8DBE98-6BE4-11DB-AE91-0012F06707F0
HistoryOct 25, 2006 - 12:00 a.m.

ruby -- cgi.rb library Denial of Service

2006-10-2500:00:00
vuxml.freebsd.org
16

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.206

Percentile

96.4%

Official ruby site reports:

A vulnerability has been discovered in the CGI library (cgi.rb)
that ships with Ruby which could be used by a malicious user to
create a denial of service attack (DoS). The problem is triggered
by sending the library an HTTP request that uses multipart MIME
encoding and as an invalid boundary specifier that begins with
“-” instead of “–”. Once triggered it will
exhaust all available memory resources effectively creating a DoS
condition.

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.206

Percentile

96.4%