Unrated severityNVD Advisory· Published Oct 20, 2004· Updated Apr 16, 2026
CVE-2004-0755
CVE-2004-0755
Description
The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.
Affected products
2cpe:2.3:a:yukihiro_matsumoto:ruby:1.6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:yukihiro_matsumoto:ruby:1.6:*:*:*:*:*:*:*
- cpe:2.3:a:yukihiro_matsumoto:ruby:1.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.debian.org/security/2004/dsa-537nvdPatchVendor Advisory
- www.gentoo.org/security/en/glsa/glsa-200409-08.xmlnvdPatchVendor Advisory
- secunia.com/advisories/12290/nvd
- www.mandriva.com/security/advisoriesnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/16996nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11128nvd
News mentions
0No linked articles in our index yet.