Vulnerability Name: | CVE-2004-0755 (CCN-16996) | ||||||||||||||||
Assigned: | 2004-07-22 | ||||||||||||||||
Published: | 2004-07-22 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions. | ||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2004-0755 Source: CCN Type: RHSA-2004-441 ruby security update Source: CCN Type: SA12290 Ruby CGI Session Management Insecure File Creation Vulnerability Source: SECUNIA Type: UNKNOWN 12290 Source: DEBIAN Type: Patch, Vendor Advisory DSA-537 Source: DEBIAN Type: DSA-537 ruby -- insecure file permissions Source: CCN Type: GLSA-200409-08 Ruby: CGI::Session creates files insecurely Source: GENTOO Type: Patch, Vendor Advisory GLSA-200409-08 Source: MANDRAKE Type: UNKNOWN MDKSA-2004:128 Source: CCN Type: BID-10946 Yukihiro Matsumoto Ruby CGI Session Management Insecure File Permissions Vulnerability Source: CCN Type: TLSA-2005-15 Two vulnerabilities discovered in Ruby Source: XF Type: UNKNOWN ruby-filestore-pstore-insecure-permission(16996) Source: XF Type: UNKNOWN ruby-filestore-pstore-insecure-permission(16996) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11128 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |