PT-2005-2939 · Ruby+1 · Libruby+1
Nobuhiro Imai
·
Published
2005-06-20
·
Updated
2017-10-11
·
CVE-2005-1992
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libruby version 1.8
Description
The issue concerns the XMLRPC server in the utils.rb file for the ruby library, where an invalid default value is set. This prevents the use of handlers for security protection, allowing remote attackers to execute arbitrary commands.
Recommendations
For libruby version 1.8, update the utils.rb file to set a valid default value to prevent remote command execution.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Libruby