PT-2011-4036 · Ruby+2 · Ruby+2
Huzaifa S. Sidhpurwala
·
Publicado
2011-08-05
·
Atualizado
2012-01-19
·
CVE-2011-2705
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ruby versions prior to 1.8.7-p352
Ruby versions 1.9.x prior to 1.9.2-p290
Description
The issue concerns the SecureRandom.random bytes function in Ruby, which relies on PID values for initialization. This reliance makes it easier for attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.
Recommendations
For Ruby versions prior to 1.8.7-p352, update to version 1.8.7-p352 or later.
For Ruby versions 1.9.x prior to 1.9.2-p290, update to version 1.9.2-p290 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Ruby
Suse