The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, which allows remote attackers to execute arbitrary commands.
References
Configurations
History
20 Nov 2024, 23:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-core/5237 - Patch | |
References | () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=315064 - | |
References | () http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html - | |
References | () http://secunia.com/advisories/16920/ - | |
References | () http://www.auscert.org.au/5509 - | |
References | () http://www.ciac.org/ciac/bulletins/p-312.shtml - | |
References | () http://www.debian.org/security/2005/dsa-748 - | |
References | () http://www.kb.cert.org/vuls/id/684913 - US Government Resource | |
References | () http://www.novell.com/linux/security/advisories/2005_18_sr.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2005-543.html - | |
References | () http://www.securityfocus.com/bid/14016 - | |
References | () http://www2.ruby-lang.org/en/20050701.html - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10819 - |
Information
Published : 2005-06-20 04:00
Updated : 2024-11-20 23:58
NVD link : CVE-2005-1992
Mitre link : CVE-2005-1992
CVE.ORG link : CVE-2005-1992
JSON object : View
Products Affected
yukihiro_matsumoto
- ruby
CWE