PT-2011-1453 · Ruby · Ruby Version Manager
Published
2011-01-20
·
Updated
2017-08-17
·
CVE-2010-3928
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ruby Version Manager (RVM) versions prior to 1.2.1
Description
The issue allows remote attackers to potentially execute arbitrary commands via a crafted file. This is related to an "escape sequence injection vulnerability" where file contents are written to a terminal without proper sanitization of non-printable characters.
Recommendations
For versions prior to 1.2.1, update to version 1.2.1 or later to resolve the issue. As a temporary workaround, consider avoiding the use of potentially crafted files until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruby Version Manager