>> Ruby "cgi.rb" Multipart MIME Request Remote Denial of Service Vulnerability
Title : Ruby "cgi.rb" Multipart MIME Request Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-4244 CVE ID : CVE-2006-5467
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-30
Technical Description
A vulnerability has been identified in Ruby, which could be exploited by remote attackers to cause a denial of service. This flaw is due to an error in "cgi.rb" when processing HTTP requests with a multipart MIME body containing an invalid boundary specifier, which could be exploited by remote attackers to exhaust all available memory resources, creating a denial of service condition.