CVE-2006-6303: Medium severity yukihiro matsumoto ruby vulnerability
Published Dec 6, 2006
·Updated
The readmultipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote attackers to cause a denial of service (infinite loop) via crafted HTTP requests, a different issue than CVE-2006-5467.
Affected Software
8 affected components
Yukihiro Matsumoto Ruby=1.8.4
Yukihiro Matsumoto Ruby=1.8.3
Yukihiro Matsumoto Ruby=1.8.1
Yukihiro Matsumoto Ruby=1.8.5
Yukihiro Matsumoto Ruby=1.8.2
Yukihiro Matsumoto Ruby=1.8.2_pre2
Yukihiro Matsumoto Ruby=1.8
Yukihiro Matsumoto Ruby=1.8.2_pre1
Remediation
Patch Available
Patch Available
Event History
Dec 6, 2006
CVE Published
07:28 PM
Data Sourced
via NVD·07:28 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 7, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6303?
CVE-2006-6303 is classified as a high severity vulnerability due to its potential to cause a denial of service through infinite loops.
2
How do I fix CVE-2006-6303?
To fix CVE-2006-6303, you should upgrade Ruby to version 1.8.5-p2 or later.
3
Which versions of Ruby are affected by CVE-2006-6303?
CVE-2006-6303 affects Ruby versions 1.8.1 through 1.8.4.
4
Can CVE-2006-6303 be exploited remotely?
Yes, CVE-2006-6303 can be exploited remotely through crafted HTTP requests.
5
Is CVE-2006-6303 related to other vulnerabilities?
CVE-2006-6303 is a different issue than CVE-2006-5467 and addresses a separate flaw in the cgi.rb library.