2.1

CVE-2004-0755

The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yukihiro Matsumoto ≫ Ruby Version 1.6
Yukihiro Matsumoto ≫ Ruby Version 1.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.281
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/12290/
http://www.debian.org/security/2004/dsa-537
Patch
Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200409-08.xml
Patch
Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2004:128
https://exchange.xforce.ibmcloud.com/vulnerabilities/16996
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11128