Nessus Plugin #15724

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[GLSA-200411-23] Ruby: Denial of Service issue

Family:
Gentoo Local Security Checks
Category:
infos
Copyright:
(C) 2004 Michel Arboi
Summary:
Ruby: Denial of Service issue
Version:
$Revision: 1.1 $
Cve_id:
CAN-2004-0983
Bugtraq_id:
-
Xrefs:
GLSA:200411-23
Description:
The remote host is affected by the vulnerability described in GLSA-200411-23
(Ruby: Denial of Service issue)


Ruby's developers found and fixed an issue in the CGI module that
can be triggered remotely and cause an infinite loop.

Impact

A remote attacker could trigger the vulnerability through an
exposed Ruby web application and cause the server to use unnecessary
CPU resources, potentially resulting in a Denial of Service.

Workaround

There is no known workaround at this time.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0983


Solution:
All Ruby 1.6.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/ruby-1.6.8-r12"
All Ruby 1.8.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/ruby-1.8.2_pre3"


Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.