CVE-2005-1992: High severity Yukihiro Matsumoto Ruby vulnerability
Published Jun 20, 2005
·Updated
The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, which allows remote attackers to execute arbitrary commands.
Affected Software
1 affected component
Yukihiro Matsumoto Ruby=1.8
Remediation
Event History
Jun 20, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1992?
CVE-2005-1992 is considered a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2005-1992?
To fix CVE-2005-1992, upgrade to a patched version of Ruby that addresses this vulnerability.
3
What software versions are affected by CVE-2005-1992?
CVE-2005-1992 affects Ruby version 1.8 specifically.
4
What attacks are possible due to CVE-2005-1992?
CVE-2005-1992 allows remote attackers to execute arbitrary commands on the server.
5
Is CVE-2005-1992 a local or remote vulnerability?
CVE-2005-1992 is a remote vulnerability, enabling attackers to exploit it over a network.