Submitted by KeesCook on Mon, 2006-04-24 12:05
Referenced CVEs:
CVE-2006-1931
Description:
===========================================================
Ubuntu Security Notice USN-273-1 April 24, 2006
ruby1.8 vulnerability
CVE-2006-1931
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)
The following packages are affected:
libruby1.8
libwebrick-ruby1.8
The problem can be corrected by upgrading the affected package to
version 1.8.1+1.8.2pre2-3ubuntu0.4 (for Ubutu 4.10),
1.8.1+1.8.2pre4-1ubuntu0.3 (for Ubuntu 5.04), or 1.8.2-9ubuntu1.1 (for
Ubuntu 5.10). In general, a standard system upgrade is sufficient to
effect the necessary changes.
Details follow:
Yukihiro Matsumoto reported that Ruby's HTTP module uses blocking
sockets. By sending large amounts of data to a server application that
uses this module, a remote attacker could exploit this to render this
application unusable and not respond any more to other clients (Denial
of Service).


