The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-lang/ruby. | Oct 30, 2017 | Apr 20, 2006 |
| Suse | — | Upgrade ruby | Feb 17, 2015 | Apr 20, 2006 |
| Ubuntu | — | Upgrade libruby1.8 | Nov 8, 2024 | Apr 20, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub