RubySec

Providing security resources for the Ruby community

CVE-2008-4310 (webrick): WEBrick Denial of Service Vulnerability

WEBrick Denial of Service Vulnerability

Published: December 08, 2008

SECURITY IDENTIFIERS

GEM

webrick

SEVERITY

CVSS v2.0: 7.8 (High)

PATCHED VERSIONS

>= 1.3.1

DESCRIPTION

httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request.

NOTE: This issue exists because of an incomplete fix for CVE-2008-3656.

RELATED