PT-2005-5567 · Ruby+1 · Ruby+1

Yutaka Oiwa

·

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2005-2337

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ruby versions 1.6.x up to 1.6.8 Ruby versions 1.8.x up to 1.8.2 Ruby version 1.9.0 development up to 2005-09-01
Description The issue allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input. Multiple vulnerabilities in the Ruby package may lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For Ruby versions 1.6.x up to 1.6.8, update to a version later than 1.6.8 to resolve the issue. For Ruby versions 1.8.x up to 1.8.2, update to a version later than 1.8.2 to resolve the issue. For Ruby version 1.9.0 development up to 2005-09-01, update to a version later than 2005-09-01 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02405
BDU:2015-02406
CVE-2005-2337
DSA-860-1
DSA-862-1
DSA-864-1
RHSA-2005:799
RHSA-2005_799

Affected Products

Red Hat
Ruby