FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-5467

This CVE name corresponds to:

Entered Topic
2006-11-04 ruby -- cgi.rb library Denial of Service

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-5467
Phase Assigned(20061023)

Description

The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, as demonstrated using a specifier that begins with a "-" instead of "--" and contains an inconsistent ID.

References

Source Reference
MLIST [mongrel-users] 20061025 [SEC] Mongrel Temporary Fix For cgi.rb 99% CPU DoS Attack
CONFIRM http://docs.info.apple.com/article.html?artnum=305530
APPLE APPLE-SA-2007-05-24
DEBIAN DSA-1234
DEBIAN DSA-1235
GENTOO GLSA-200611-12
MANDRIVA MDKSA-2006:192
OPENPKG OpenPKG-SA-2006.030
REDHAT RHSA-2006:0729
SGI 20061101-01-P
SUSE SUSE-SR:2006:026
UBUNTU USN-371-1
BID 20777
OVAL oval:org.mitre.oval:def:10185
VUPEN ADV-2006-4244
VUPEN ADV-2006-4245
VUPEN ADV-2007-1939
SECTRACK 1017194
SECUNIA 22615
SECUNIA 22624
SECUNIA 22761
SECUNIA 22929
SECUNIA 23040
SECUNIA 23344
SECUNIA 22932
SECUNIA 25402