CVE Vulnerabilities

CVE-2004-0755

Published: Oct 20, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.

Affected Software

NameVendorStart VersionEnd Version
RubyYukihiro_matsumoto1.6 (including)1.6 (including)
RubyYukihiro_matsumoto1.8 (including)1.8 (including)
Red Hat Enterprise Linux 3RedHatruby-0:1.6.8-9.EL3.2*
Ruby1.6Ubuntudapper*
Ruby1.8Ubuntudapper*
Ruby1.8Ubuntudevel*
Ruby1.8Ubuntuedgy*
Ruby1.8Ubuntufeisty*

References