PT-2011-2808 · Ruby+1 · Ruby+1

Jan Lieskovsky

·

Publicado

2011-03-02

·

Atualizado

2012-05-12

·

CVE-2011-1004

CVSS v2.0

6.3

Média

VetorAV:L/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ruby versions 1.8.6 through 1.8.6-420 Ruby versions 1.8.7 through 1.8.7-330 Ruby version 1.8.8dev Ruby versions 1.9.1 through 1.9.1-430 Ruby versions 1.9.2 through 1.9.2-136 Ruby version 1.9.3dev
Description The issue allows local users to delete arbitrary files via a symlink attack, exploiting the FileUtils.remove entry secure method. This method is vulnerable to a symlink attack, enabling attackers to delete files they should not have access to.
Recommendations For Ruby versions 1.8.6 through 1.8.6-420, consider disabling the FileUtils.remove entry secure method until a patch is available. For Ruby versions 1.8.7 through 1.8.7-330, consider disabling the FileUtils.remove entry secure method until a patch is available. For Ruby version 1.8.8dev, consider disabling the FileUtils.remove entry secure method until a patch is available. For Ruby versions 1.9.1 through 1.9.1-430, consider disabling the FileUtils.remove entry secure method until a patch is available. For Ruby versions 1.9.2 through 1.9.2-136, consider disabling the FileUtils.remove entry secure method until a patch is available. For Ruby version 1.9.3dev, consider disabling the FileUtils.remove entry secure method until a patch is available.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1004
RHSA-2011:0909
RHSA-2011:0910
RHSA-2011_0909
RHSA-2011_0910

Produtos afetados

Red Hat
Ruby