Family: Red Hat Local Security Checks --> Category: infos
RHSA-2004-635: irb Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the irb packages
Detailed Explanation for this Vulnerability Test
An updated ruby package that fixes a denial of service issue for the CGI
instance is now available.
Ruby is an interpreted scripting language for object-oriented programming.
A flaw was dicovered in the CGI module of Ruby. If empty data is sent by
the POST method to the CGI script which requires MIME type
multipart/form-data, it can get stuck in a loop. A remote attacker could
trigger this flaw and cause a denial of service. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CVE-2004-0983 to this issue.
Users are advised to upgrade to this erratum package, which contains a
backported patch to cgi.rb.
Solution : http://rhn.redhat.com/errata/RHSA-2004-635.html
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.