PT-2006-7548 · Ruby+1 · Ruby+1

Sergey Matveychuk

·

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2006-3694

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ruby versions prior to 1.8.5
Description The issue involves multiple unspecified vulnerabilities that allow remote attackers to bypass "safe level" checks. This can be achieved through unspecified vectors involving the alias function and directory operations. The vulnerabilities may lead to a breach of confidentiality and integrity of protected information and can be exploited remotely.
Recommendations For versions prior to 1.8.5, update to version 1.8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the alias function and directory operations until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01757
BDU:2015-01758
CVE-2006-3694
DSA-1139-1
DSA-1157
RHSA-2006:0604
RHSA-2006_0604

Affected Products

Red Hat
Ruby