Secunia Logo
 
CVE Reference: CVE-2006-4112
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-4112

Description:
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/28364

SUSE
  http://www.novell.com/linux/security/advisories/2006_21_sr.html

ST
  1016673

SAID
  Secunia Advisory: SA21424
  Secunia Advisory: SA21466
  Secunia Advisory: SA21749

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200608-20.xml

CONFIRM
  http://weblog.rubyonrails.org/2006/8/10/rails-1-1-6-backports-and-full-disclosure

CERT-VN
  699540

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/442934/100/0/threaded

BID
  19454


Return to the previous page.