Another DoS Vulnerability in CGI Library
Another vulnerability has been discovered in the CGI library (cgi.rb) that ships with Ruby which could be used by a malicious user to create a denial of service attack (DoS).
Impact:
A specific HTTP request for any web application using cgi.rb causes CPU consumption on the machine on which the web application is running. Many such requests result in a denial of service.
Vulnerable versions:
– 1.8 series: 1.8.5 and all prior versions
– Development version (1.9 series): All versions before 2006-12-04
)
comments : 0 Add comment
