Lucene search

K
ubuntucveUbuntu.comUB:CVE-2005-1992
HistoryJun 20, 2005 - 12:00 a.m.

CVE-2005-1992

2005-06-2000:00:00
ubuntu.com
ubuntu.com
12

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.036

Percentile

91.7%

The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an
invalid default value that prevents “security protection” using handlers,
which allows remote attackers to execute arbitrary commands.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchruby1.8< 1.8.4-1ubuntu1.3UNKNOWN
ubuntu6.10noarchruby1.8< 1.8.4-5ubuntu1.2UNKNOWN
ubuntu7.04noarchruby1.8< 1.8.5-4ubuntu2UNKNOWN
ubuntu6.06noarchruby1.9< 1.9.0+20060423-3ubuntu1UNKNOWN
ubuntu6.10noarchruby1.9< 1.9.0+20060423-3ubuntu1UNKNOWN
ubuntu7.04noarchruby1.9< 1.9.0+20060423-3ubuntu1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.036

Percentile

91.7%