Unrated severityNVD Advisory· Published Oct 27, 2006· Updated Apr 23, 2026
CVE-2006-5467
CVE-2006-5467
Description
The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, as demonstrated using a specifier that begins with a "-" instead of "--" and contains an inconsistent ID.
Affected products
1- cpe:2.3:a:yukihiro_matsumoto:ruby:1.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
26- patches.sgi.com/support/free/security/advisories/20061101-01-PnvdPatchVendor Advisory
- secunia.com/advisories/22615nvdPatchVendor Advisory
- secunia.com/advisories/22624nvdPatchVendor Advisory
- secunia.com/advisories/22761nvdPatchVendor Advisory
- secunia.com/advisories/22929nvdPatchVendor Advisory
- secunia.com/advisories/23040nvdPatchVendor Advisory
- secunia.com/advisories/23344nvdPatchVendor Advisory
- security.gentoo.org/glsa/glsa-200611-12.xmlnvdPatchVendor Advisory
- securitytracker.com/idnvdPatch
- www.novell.com/linux/security/advisories/2006_26_sr.htmlnvdPatchVendor Advisory
- www.openpkg.org/security/advisories/OpenPKG-SA-2006.030-ruby.htmlnvdPatchVendor Advisory
- www.redhat.com/support/errata/RHSA-2006-0729.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/20777nvdPatch
- www.ubuntu.com/usn/usn-371-1nvdPatch
- secunia.com/advisories/22932nvdVendor Advisory
- secunia.com/advisories/25402nvdVendor Advisory
- www.vupen.com/english/advisories/2006/4244nvdVendor Advisory
- www.vupen.com/english/advisories/2006/4245nvdVendor Advisory
- www.vupen.com/english/advisories/2007/1939nvdVendor Advisory
- docs.info.apple.com/article.htmlnvd
- lists.apple.com/archives/security-announce/2007/May/msg00004.htmlnvd
- rubyforge.org/pipermail/mongrel-users/2006-October/001946.htmlnvd
- www.debian.org/security/2006/dsa-1234nvd
- www.debian.org/security/2006/dsa-1235nvd
- www.mandriva.com/security/advisoriesnvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10185nvd
News mentions
0No linked articles in our index yet.