Unrated severityNVD Advisory· Published Dec 6, 2006· Updated Apr 23, 2026
CVE-2006-6303
CVE-2006-6303
Description
The read_multipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote attackers to cause a denial of service (infinite loop) via crafted HTTP requests, a different issue than CVE-2006-5467.
Affected products
8cpe:2.3:a:yukihiro_matsumoto:ruby:1.8:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:yukihiro_matsumoto:ruby:1.8:*:*:*:*:*:*:*
- cpe:2.3:a:yukihiro_matsumoto:ruby:1.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:yukihiro_matsumoto:ruby:1.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:yukihiro_matsumoto:ruby:1.8.2_pre1:*:*:*:*:*:*:*
- cpe:2.3:a:yukihiro_matsumoto:ruby:1.8.2_pre2:*:*:*:*:*:*:*
- cpe:2.3:a:yukihiro_matsumoto:ruby:1.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:yukihiro_matsumoto:ruby:1.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:yukihiro_matsumoto:ruby:1.8.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
24- bugs.gentoo.org/show_bug.cginvdPatch
- bugzilla.redhat.com/bugzilla/show_bug.cginvdPatch
- www.ruby-lang.org/cgi-bin/cvsweb.cgi/ruby/lib/cgi.rb.diffnvdPatch
- www.ruby-lang.org/en/news/2006/12/04/another-dos-vulnerability-in-cgi-library/nvdPatch
- docs.info.apple.com/article.htmlnvd
- jvn.jp/jp/JVN%2384798830/index.htmlnvd
- lists.apple.com/archives/security-announce/2007/May/msg00004.htmlnvd
- secunia.com/advisories/23165nvd
- secunia.com/advisories/23268nvd
- secunia.com/advisories/23454nvd
- secunia.com/advisories/25402nvd
- secunia.com/advisories/27576nvd
- secunia.com/advisories/31090nvd
- security.gentoo.org/glsa/glsa-200612-21.xmlnvd
- securitytracker.com/idnvd
- www.mandriva.com/security/advisoriesnvd
- www.novell.com/linux/security/advisories/2007_4_sr.htmlnvd
- www.redhat.com/support/errata/RHSA-2007-0961.htmlnvd
- www.securityfocus.com/bid/21441nvd
- www.ubuntu.com/usn/usn-394-1nvd
- www.vupen.com/english/advisories/2006/4855nvd
- www.vupen.com/english/advisories/2007/1939nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/30734nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10529nvd
News mentions
0No linked articles in our index yet.