5

CVE-2006-6303

The read_multipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote attackers to cause a denial of service (infinite loop) via crafted HTTP requests, a different issue than CVE-2006-5467.

Data is provided by the National Vulnerability Database (NVD)
Yukihiro MatsumotoRuby Version1.8
Yukihiro MatsumotoRuby Version1.8.1
Yukihiro MatsumotoRuby Version1.8.2
Yukihiro MatsumotoRuby Version1.8.2_pre1
Yukihiro MatsumotoRuby Version1.8.2_pre2
Yukihiro MatsumotoRuby Version1.8.3
Yukihiro MatsumotoRuby Version1.8.4
Yukihiro MatsumotoRuby Version1.8.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.27% 0.867
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P