VDB
CVE-2006-1931
CVE-2006-1931
PUBLISHED
CVSS 5 MEDIUM
The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.
EPSS 13.21% · 94.3th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
13.21%
94.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| yukihiro_matsumoto | ruby | 1.8.1, 1.6.1, 1.6.2 |
| n/a | n/a | n/a |
Timeline
- Apr 20, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 3, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 19772 third-party-advisory
- http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-dev/27787 url
- 21657 third-party-advisory
- 16904 third-party-advisory
- ftp://ftp.ruby-lang.org/pub/ruby/1.8/ruby-1.8.2-webrick-dos-1.patch url
- USN-273-1 vendor-advisory
- 20024 third-party-advisory
- 17645 vdb
- oval:org.mitre.oval:def:11100 vdb
- SUSE-SR:2006:012 vendor-advisory
- RHSA-2006:0427 vendor-advisory
- ruby-socket-dos(26102) vdb
- GLSA-200605-11 vendor-advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189540 url
- 1015978 vdb
- DSA-1157 vendor-advisory
- 19804 third-party-advisory
- MDKSA-2006:079 vendor-advisory
- 20064 third-party-advisory
- 20457 third-party-advisory
…and 4 more