|
Family: Ubuntu Local Security Checks --> Category: infos
USN20-1 : ruby1.8 vulnerability Vulnerability Scan
Vulnerability Scan Summary ruby1.8 vulnerability
Detailed Explanation for this Vulnerability Test
Synopsis :
These remote packages are missing security patches :
- irb1.8
- libbigdecimal-ruby1.8
- libcurses-ruby1.8
- libdbm-ruby1.8
- libdl-ruby1.8
- libdrb-ruby1.8
- liberb-ruby1.8
- libgdbm-ruby1.8
- libiconv-ruby1.8
- libopenssl-ruby1.8
- libpty-ruby1.8
- libracc-runtime-ruby1.8
- libreadline-ruby1.8
- librexml-ruby1.8
- libruby1.8
- libruby1.8-dbg
- libsdbm-ruby1.8
- libsoap-ruby1.8
- libstrscan-ruby1.8
- libsyslog-ruby1.8
- libtcltk-ruby1.8
- libtest-unit-ruby1.8
- libtk-ruby1.8
- libweb
[...]
Description :
The Ruby developers discovered a potential Denial of Service
vulnerability in the CGI module (cgi.rb). Specially crafted CGI
requests could cause an infinite loop in the server process.
Repetitive attacks could use most of the available processor
resources, exhaust the number of allowed parallel connections in web
servers, or cause similar effects which render the service
unavailable.
There is no possibility of privilege escalation or data loss.
Solution :
Upgrade to :
- irb1.8-1.8.1+1.8.2pre2-3ubuntu0.1 (Ubuntu 4.10)
- libbigdecimal-ruby1.8-1.8.1+1.8.2pre2-3ubuntu0.1 (Ubuntu 4.10)
- libcurses-ruby1.8-1.8.1+1.8.2pre2-3ubuntu0.1 (Ubuntu 4.10)
- libdbm-ruby1.8-1.8.1+1.8.2pre2-3ubuntu0.1 (Ubuntu 4.10)
- libdl-ruby1.8-1.8.1+1.8.2pre2-3ubuntu0.1 (Ubuntu 4.10)
- libdrb-ruby1.8-1.8.1+1.8.2pre2-3ubuntu0.1 (Ubuntu 4.10)
- liberb-ruby1.8-1.8.1+1.8.2pre2-3ubuntu0.1 (Ubuntu 4.10)
- libgdbm-ruby1.8-1.8.1+1.8.2pre2-3ubuntu0.1 (Ubuntu 4.10)
- libiconv-ruby1.8-1.8.1+1.8.2p
[...]
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|