Red Hat Bugzilla – Bug 458953
CVE-2008-3656 ruby: WEBrick DoS vulnerability (CPU consumption)
Last modified: 2011-07-28 06:56:08 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-3656 to the following vulnerability:
Algorithmic complexity vulnerability in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.5 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.
Created attachment 314212 [details]
ruby-22.214.171.1247-2.fc8 has been submitted as an update for Fedora 8.
ruby-126.96.36.1997-2.fc9 has been submitted as an update for Fedora 9.
ruby-188.8.131.527-2.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
ruby-184.108.40.2067-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Created attachment 322637 [details]
Correct patch for this issue
The previous patch is actually for CVE-2008-1145.
This is the proper patch for CVE-2008-3656