[Ruby] FW: GLSA 200611-12 ] Ruby: Denial of Service vulnerability
Daevid Vincent
daevid at daevid.com
Mon Nov 20 13:17:06 PST 2006
Might be of interest...
DÆVID
-----Original Message-----
From: Sune Kloppenborg Jeppesen [mailto:jaervosz at gentoo.org]
Sent: Monday, November 20, 2006 11:39 AM
To: gentoo-announce at lists.gentoo.org
Cc: bugtraq at securityfocus.com; full-disclosure at lists.grok.org.uk;
security-alerts at linuxsecurity.com
Subject: [gentoo-announce] [ GLSA 200611-12 ] Ruby: Denial of Service
vulnerability
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200611-12
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: Ruby: Denial of Service vulnerability
Date: November 20, 2006
Bugs: #153497
ID: 200611-12
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
The Ruby cgi.rb CGI library is vulnerable to a Denial of Service
attack.
Background
==========
Ruby is a dynamic, open source programming language with a focus on
simplicity and productivity.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-lang/ruby < 1.8.5-r3 >= 1.8.5-r3
Description
===========
Zed Shaw, Jeremy Kemper, and Jamis Buck of the Mongrel project reported
that the CGI library shipped with Ruby is vulnerable to a remote Denial
of Service by an unauthenticated user.
Impact
======
The vulnerability can be exploited by sending the cgi.rb library an
HTTP request with multipart MIME encoding that contains a malformed
MIME boundary specifier beginning with "-" instead of "--". Successful
exploitation of the vulnerability causes the library to go into an
infinite loop waiting for additional non-existent input.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All Ruby users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/ruby-1.8.5-r3"
References
==========
[ 1 ] CVE-2006-5467
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5467
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-200611-12.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security at gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.
License
=======
Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/2.5
More information about the Ruby
mailing list