CVE-2006-6303

説明

CVE.org より

The read_multipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote attackers to cause a denial of service (infinite loop) via crafted HTTP requests, a different issue than CVE-2006-5467.

詳細

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

脆弱性の原因 (CWE) の理解

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Amplification

An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.

よくある質問

エラータ通知の受信を希望しますか? こちらで登録してください。