CVE-2004-0983

Publication date 1 March 2005

Last updated 24 July 2024


Ubuntu priority

The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.

Status

Package Ubuntu Release Status
ruby1.6 7.04 feisty Not in release
6.10 edgy Not in release
6.06 LTS dapper
Fixed 1.6.8-13ubuntu1
ruby1.8 7.04 feisty
Fixed 1.8.5-4ubuntu2
6.10 edgy
Fixed 1.8.4-5ubuntu1.2
6.06 LTS dapper
Fixed 1.8.4-1ubuntu1.3

References

Related Ubuntu Security Notices (USN)

    • USN-20-1
    • Ruby CGI module vulnerability
    • 9 November 2004

Other references