VDB
CVE-2006-1931
CVE-2006-1931
PUBLISHED
CVSS 5 MEDIUM
The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.
EPSS 10.43% · 95.6th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
10.43%
95.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| yukihiro_matsumoto | ruby | 1.8.1, 1.6.1, 1.6.2 |
| n/a | n/a | n/a |
Timeline
- Apr 20, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Sep 13, 2023 EPSS Score
References
- ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.2-webrick-dos-1.patch url
- USN-273-1 vendor-advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189540 url
- DSA-1157 vendor-advisory
- 20064 third-party-advisory
- oval:org.mitre.oval:def:11100 vdb
- SUSE-SR:2006:012 vendor-advisory
- RHSA-2006:0427 vendor-advisory
- 20457 third-party-advisory
- ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.2-xmlrpc-dos-1.patch technical
- http://secunia.com/advisories/16904 technical
- http://secunia.com/advisories/20024 technical
- http://www.osvdb.org/24972 technical
- http://secunia.com/advisories/19772 technical
- http://www.gentoo.org/security/en/glsa/glsa-200605-11.xml technical
- http://www.securityfocus.com/bid/17645 technical
- https://nvd.nist.gov/vuln/detail/CVE-2006-1931 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26102 url
- https://usn.ubuntu.com/273-1 url
- http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-dev/27787 url
…and 4 more