Back

MEDIUM

ruby's cgi.rb vulnerable infinite loop DoS

Published Dec 6, 2006

Description

The read_multipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote attackers to cause a denial of service (infinite loop) via crafted HTTP requests, a different issue than CVE-2006-5467.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Weaknesses (2)

References (29)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 6, 2006
Updated Aug 7, 2024
Reserved Dec 5, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Dec 4, 2006
ENISA EUVD
Assigner mitre
Published Dec 6, 2006
Updated Aug 7, 2024
Exploited since n/a
EUVD-2006-6286