Ruby is an interpreted scripting language for object-oriented programming.
A flaw was dicovered in the CGI module of Ruby. If empty data is sent by
the POST method to the CGI script which requires MIME type
multipart/form-data, it can get stuck in a loop. A remote attacker could
trigger this flaw and cause a denial of service. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0983 to this issue.
Users are advised to upgrade to this erratum package, which contains a
backported patch to cgi.rb.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | any | ia64 | irb | < 1.6.8-9.EL3.3 | irb-1.6.8-9.EL3.3.ia64.rpm |
RedHat | any | i386 | ruby-mode | < 1.6.8-9.EL3.3 | ruby-mode-1.6.8-9.EL3.3.i386.rpm |
RedHat | any | s390x | ruby | < 1.6.8-9.EL3.3 | ruby-1.6.8-9.EL3.3.s390x.rpm |
RedHat | any | ia64 | ruby-mode | < 1.6.8-9.EL3.3 | ruby-mode-1.6.8-9.EL3.3.ia64.rpm |
RedHat | any | i386 | ruby-docs | < 1.6.8-9.EL3.3 | ruby-docs-1.6.8-9.EL3.3.i386.rpm |
RedHat | any | s390x | ruby-mode | < 1.6.8-9.EL3.3 | ruby-mode-1.6.8-9.EL3.3.s390x.rpm |
RedHat | any | ia64 | ruby-libs | < 1.6.8-9.EL3.3 | ruby-libs-1.6.8-9.EL3.3.ia64.rpm |
RedHat | any | ppc | ruby-tcltk | < 1.6.8-9.EL3.3 | ruby-tcltk-1.6.8-9.EL3.3.ppc.rpm |
RedHat | any | i386 | irb | < 1.6.4-2.AS21.1 | irb-1.6.4-2.AS21.1.i386.rpm |
RedHat | any | s390 | ruby-docs | < 1.6.8-9.EL3.3 | ruby-docs-1.6.8-9.EL3.3.s390.rpm |