Search

published date: March 1, 2005

CVE-2004-0983 : Denial of Service Vulnerability

Description

The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.

Product(s):

  • Yukihiro Matsumoto Ruby 1.6.7
  • Yukihiro Matsumoto Ruby 1.6
  • Yukihiro Matsumoto Ruby 1.8.1
  • Yukihiro Matsumoto Ruby 1.8.2 Pre1
  • Yukihiro Matsumoto Ruby 1.8.2 Pre2
  • Yukihiro Matsumoto Ruby 1.8

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-0983, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-0983 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?