First published: Tue Nov 13 2007(Updated: )
Ruby is an interpreted scripting language for object-oriented programming.<br>A flaw was discovered in the way Ruby's CGI module handles certain HTTP<br>requests. If a remote attacker sends a specially crafted request, it is<br>possible to cause the ruby CGI script to enter an infinite loop, possibly<br>causing a denial of service. (CVE-2006-6303)<br>An SSL certificate validation flaw was discovered in several Ruby Net<br>modules. The libraries were not checking the requested host name against<br>the common name (CN) in the SSL server certificate, possibly allowing a man<br>in the middle attack. (CVE-2007-5162, CVE-2007-5770)<br>Users of Ruby should upgrade to these updated packages, which contain<br>backported patches to resolve these issues.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.