CVE-2006-1931: Medium severity Yukihiro Matsumoto Ruby vulnerability
Published Apr 20, 2006
·Updated
The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.
Affected Software
10 affected components
Yukihiro Matsumoto Ruby=1.6.5
Yukihiro Matsumoto Ruby=1.6.4
Yukihiro Matsumoto Ruby=1.8.1
Yukihiro Matsumoto Ruby=1.6.2
Yukihiro Matsumoto Ruby=1.6.3
Yukihiro Matsumoto Ruby=1.6.6
Yukihiro Matsumoto Ruby=1.6.7
Yukihiro Matsumoto Ruby=1.6
Yukihiro Matsumoto Ruby=1.8
Yukihiro Matsumoto Ruby=1.6.1
Remediation
Patch Available
Event History
Apr 20, 2006
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1931?
CVE-2006-1931 has a severity that allows attackers to cause a denial of service via blocked connections.
2
How do I fix CVE-2006-1931?
To fix CVE-2006-1931, upgrade Ruby to version 1.8.2 or later.
3
Which versions of Ruby are affected by CVE-2006-1931?
CVE-2006-1931 affects Ruby versions 1.6.1 to 1.8.1.
4
What type of attack does CVE-2006-1931 enable?
CVE-2006-1931 enables denial of service attacks through the exploitation of blocking sockets.
5
Who is the vendor of the software affected by CVE-2006-1931?
The vendor of the software affected by CVE-2006-1931 is Yukihiro Matsumoto, the creator of Ruby.