Name | CVE-2006-1931 |
Description | The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1157 |
Debian Bugs | 365520 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
ruby1.8 | source | sarge | 1.8.2-7sarge4 | DSA-1157 | ||
ruby1.8 | source | (unstable) | 1.8.3 | 365520 |
the redhat bugzilla entry says this is fixed in 1.8.3