PT-2005-2939 · Ruby+1 · Libruby+1

Nobuhiro Imai

·

Published

2005-06-20

·

Updated

2017-10-11

·

CVE-2005-1992

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libruby version 1.8
Description The issue concerns the XMLRPC server in the utils.rb file for the ruby library, where an invalid default value is set. This prevents the use of handlers for security protection, allowing remote attackers to execute arbitrary commands.
Recommendations For libruby version 1.8, update the utils.rb file to set a valid default value to prevent remote command execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1992
DSA-748-1
RHSA-2005:543
RHSA-2005_543

Affected Products

Red Hat
Libruby