CVE-2008-4310: High severity ruby vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-3656 to the following vulnerability:
Algorithmic complexity vulnerability in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.5 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.
Refences: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494401 http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/
Vincent Danen from LinSec discovered the original patch for this flaw, provided by Red Hat, did not properly address this flaw.
Other sources
httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request. NOTE: this issue exists because of an incomplete fix for CVE-2008-3656.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4310?
CVE-2008-4310 is classified as a medium severity vulnerability affecting Ruby's WEBrick.
How do I fix CVE-2008-4310?
To fix CVE-2008-4310, upgrade Ruby to the versions 1.8.1-7.el4_7.2 or 1.8.5-5.el5_2.6, or update WEBrick to version 1.3.1.
Which versions of Ruby are affected by CVE-2008-4310?
CVE-2008-4310 affects Ruby versions 1.8.1 through 1.8.5 and earlier.
What is the nature of the vulnerability described in CVE-2008-4310?
CVE-2008-4310 involves an algorithmic complexity vulnerability in WEBrick::HTTP::DefaultFileHandler.
What software packages are associated with CVE-2008-4310?
CVE-2008-4310 is associated with Ruby versions 1.8.1 and 1.8.5, and WEBrick versions before 1.3.1.