Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://rubyforge.org/pipermail/mongrel-users/2006-October/001946.html http://www.vuxml.org/freebsd/ab8dbe98-6be4-11db-ae91-0012f06707f0.html
Insight
The following packages are affected:
ruby
ruby_static
CVE-2006-5467
The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a dneial of service (infinite loop and CPU consumption) via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, as demonstrated using a specifier that begins with a '-' instead of '--' and contains an inconsistent ID.
Severity
Classification
-
CVE CVE-2006-5467 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities