Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.ruby-lang.org/en/news/2010/08/16/xss-in-webrick-cve-2010-0541/ http://www.vuxml.org/freebsd/34e0316a-aa91-11df-8c2e-001517289bf8.html
Insight
The following packages are affected:
ruby
ruby+pthreads
ruby+pthreads+oniguruma
ruby+oniguruma
CVE-2010-0541
Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote attackers to inject arbitrary web script or HTML via a crafted URI that triggers a UTF-7 error page.
Severity
Classification
-
CVE CVE-2010-0541 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities