LOW · 2.1

CVE-2004-0755

The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessio...

Vulnerability Description

The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Yukihiro MatsumotoRuby1.6

References

FAQ

What is CVE-2004-0755?

CVE-2004-0755 is a vulnerability with a CVSS score of 2.1 (LOW). The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessio...

How severe is CVE-2004-0755?

CVE-2004-0755 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0755?

Check the references section above for vendor advisories and patch information. Affected products include: Yukihiro Matsumoto Ruby.