CVE Vulnerabilities

CVE-2005-1992

Published: Jun 20, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents security protection using handlers, which allows remote attackers to execute arbitrary commands.

Affected Software

NameVendorStart VersionEnd Version
RubyYukihiro_matsumoto1.8 (including)1.8 (including)
Red Hat Enterprise Linux 4RedHatruby-0:1.8.1-7.EL4.1*
Ruby1.8Ubuntudapper*
Ruby1.8Ubuntudevel*
Ruby1.8Ubuntuedgy*
Ruby1.8Ubuntufeisty*
Ruby1.9Ubuntudapper*
Ruby1.9Ubuntudevel*
Ruby1.9Ubuntuedgy*
Ruby1.9Ubuntufeisty*

References