CVE-2004-0983: Medium severity yukihiro matsumoto ruby vulnerability
Published Nov 19, 2004
·Updated
The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.
Affected Software
17 affected components
Yukihiro Matsumoto Ruby=1.8.1
Yukihiro Matsumoto Ruby=1.8.2_pre2
Yukihiro Matsumoto Ruby=1.6.7
Yukihiro Matsumoto Ruby=1.6
Yukihiro Matsumoto Ruby=1.8
Yukihiro Matsumoto Ruby=1.8.2_pre1
Mandrakesoft Mandrake Linux Corporate Server=2.1
Ubuntu Ubuntu Linux=4.1
Mandrakesoft Mandrake Linux=9.2
Mandrakesoft Mandrake Linux=10.1
Mandrakesoft Mandrake Linux=9.2
Mandrakesoft Mandrake Linux=10.0
Ubuntu Ubuntu Linux=4.1
Gentoo Linux
Mandrakesoft Mandrake Linux Corporate Server=2.1
Mandrakesoft Mandrake Linux=10.0
Mandrakesoft Mandrake Linux=10.1
Remediation
Patch Available
Event History
Nov 19, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0983?
CVE-2004-0983 is classified as a denial of service vulnerability that can lead to infinite loops and high CPU consumption.
2
How do I fix CVE-2004-0983?
To fix CVE-2004-0983, upgrade Ruby to version 1.6.8 or 1.8.2 or later.
3
Who is affected by CVE-2004-0983?
CVE-2004-0983 affects Ruby versions prior to 1.6.8 and 1.8.2, as well as various distributions like Mandrake Linux and Ubuntu.
4
What types of attacks can exploit CVE-2004-0983?
CVE-2004-0983 can be exploited through specially crafted HTTP requests that cause denial of service.
5
Is there a risk of data loss with CVE-2004-0983?
CVE-2004-0983 primarily results in denial of service and CPU exhaustion, with no direct data loss associated.