CVE-2008-4310

Ruby < 1.3.1 - Resource Management Error

Title source: rule

Description

httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request. NOTE: this issue exists because of an incomplete fix for CVE-2008-3656.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Keita Yamaguchi · rubydosmultiple
https://www.exploit-db.com/exploits/32222

Scores

EPSS 0.0579
EPSS Percentile 90.5%

Details

CWE
CWE-399
Status published
Products (3)
rubygems/webrick 0 - 1.3.1RubyGems
ruby-lang/ruby 1.8.1
ruby-lang/ruby 1.8.5
Published Dec 09, 2008
Tracked Since Feb 18, 2026