Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Gentoo Local Security Checks --> Category: infos

[GLSA-200411-23] Ruby: Denial of Service issue Vulnerability Scan


Vulnerability Scan Summary
Ruby: Denial of Service issue

Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200411-23
(Ruby: Denial of Service issue)


Ruby's developers found and fixed an issue in the CGI module that
can be triggered remotely and cause an infinite loop.

Impact

A remote attacker could trigger the vulnerability through an
exposed Ruby web application and cause the server to use unnecessary
CPU resources, potentially resulting in a Denial of Service.

Workaround

There is no known workaround at this time.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0983


Solution:
All Ruby 1.6.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/ruby-1.6.8-r12"
All Ruby 1.8.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/ruby-1.8.2_pre3"


Threat Level: Medium


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.