CVE Vulnerabilities

CVE-2005-1992

Published: Jun 20, 2005 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents security protection using handlers, which allows remote attackers to execute arbitrary commands.

Affected Software

Name Vendor Start Version End Version
Ruby Yukihiro_matsumoto 1.8 (including) 1.8 (including)
Red Hat Enterprise Linux 4 RedHat ruby-0:1.8.1-7.EL4.1 *
Ruby1.8 Ubuntu dapper *
Ruby1.8 Ubuntu devel *
Ruby1.8 Ubuntu edgy *
Ruby1.8 Ubuntu feisty *
Ruby1.9 Ubuntu dapper *
Ruby1.9 Ubuntu devel *
Ruby1.9 Ubuntu edgy *
Ruby1.9 Ubuntu feisty *

References