CVE-2004-0983

9 documents6 sources
Severity
5.0MEDIUM
EPSS
1.1%
top 21.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateApr 29

Description

The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

Also affects: Ubuntu Linux 4.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f94p-wf3v-wp5p: The CGI module in Ruby 12022-04-29
CVEList
CVE-2004-0983: The CGI module in Ruby 12004-11-19

📋Vendor Advisories

2
Ubuntu
Ruby CGI module vulnerability2004-11-09
Red Hat
security flaw2004-11-08

💬Community

3
Bugzilla
CVE-2004-0983 security flaw2018-08-16
Bugzilla
CVE-2006-5467 Ruby CGI multipart parsing DoS2006-10-26
Bugzilla
CVE-2006-5467 Ruby CGI multipart parsing DoS2006-10-25