PT-2011-4036 · Ruby+2 · Ruby+2
Huzaifa S. Sidhpurwala
·
Published
2011-08-05
·
Updated
2012-01-19
·
CVE-2011-2705
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ruby versions prior to 1.8.7-p352
Ruby versions 1.9.x prior to 1.9.2-p290
Description
The issue concerns the SecureRandom.random bytes function in Ruby, which relies on PID values for initialization. This reliance makes it easier for attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.
Recommendations
For Ruby versions prior to 1.8.7-p352, update to version 1.8.7-p352 or later.
For Ruby versions 1.9.x prior to 1.9.2-p290, update to version 1.9.2-p290 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Ruby
Suse