Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 11 additions & 2 deletions rubies/jruby/CVE-2011-4838.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,23 @@
engine: jruby
cve: 2011-4838
osvdb: 78116
url: http://jruby.org/2011/12/27/jruby-1-6-5-1
ghsa: cgqc-fqxr-q6r6
url: http://jruby.org/2011/12/27/jruby-1-6-5-1.html
title: "CVE-2011-4838 jruby: hash table collisions DoS (oCERT-2011-003)"
date: 2011-12-27
description: |
JRuby before 1.6.5.1 computes hash values without restricting the ability
to trigger hash collisions predictably, which allows context-dependent attackers
to cause a denial of service (CPU consumption) via crafted input to an application
that maintains a hash table.
cvss_v2: 7.8
cvss_v2: 5.0
patched_versions:
- ">= 1.6.5.1"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2011-4838
- http://jruby.org/2011/12/27/jruby-1-6-5-1.html
- http://www.ocert.org/advisories/ocert-2011-003.html
- https://www.kb.cert.org/vuls/id/903934
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72019
- https://github.com/advisories/GHSA-cgqc-fqxr-q6r6
33 changes: 33 additions & 0 deletions rubies/ruby/CVE-2006-5467.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
---
engine: ruby
cve: 2006-5467
ghsa: cgqx-jwj4-2jc4
url: https://nvd.nist.gov/vuln/detail/CVE-2006-5467
title: Denial of service vulnerabilities in the Ruby CGI
date: 2006-10-27
description: |
The cgi.rb CGI library for Ruby 1.8 allows remote attackers to
cause a denial of service (infinite loop and CPU consumption) via
an HTTP request with a multipart MIME body that contains an invalid
boundary specifier, as demonstrated using a specifier that begins
with a "-" instead of "--" and contains an inconsistent ID.
cvss_v2: 5.0
patched_versions:
- "~> 1.8.5-p2"
- ">= 1.9.0"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2006-5467
- https://www.ruby-lang.org/en/news/2006/11/03/CVE-2006-5467
- https://www.ruby-lang.org/en/news/2006/12/04/another-dos-vulnerability-in-cgi-library
- https://cache.ruby-lang.org/pub/ruby/1.8/ruby-1.8.5-cgi-dos-1.patch
- http://rubyforge.org/pipermail/mongrel-users/2006-October/001946.html
- https://bugzilla.redhat.com/show_bug.cgi?id=212237
- https://jvn.jp/en/jp/JVN84798830/index.html
- http://security.gentoo.org/glsa/glsa-200611-12.xml
- https://ubuntu.com/security/notices/USN-371-1
- http://www.debian.org/security/2006/dsa-1234
- https://lists.debian.org/debian-security-announce/2006/msg00337.html
- https://web.archive.org/web/20071214135617/http://docs.info.apple.com/article.html?artnum=305530
- https://web.archive.org/web/20080221113337/http://lists.apple.com/archives/security-announce/2007/May/msg00004.html
- https://github.com/advisories/GHSA-cgqx-jwj4-2jc4