PT-2012-5459 · Ruby+3 · Ruby+3

Peter Bex

·

Published

2012-11-24

·

Updated

2016-10-03

·

CVE-2012-4522

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ruby versions 1.9.3 before patchlevel 286 Ruby versions 2.0.0 before r37163
Description The issue allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path. This is due to a problem in the rb get path check function in file.c.
Recommendations For Ruby versions 1.9.3 before patchlevel 286, update to patchlevel 286 or later. For Ruby versions 2.0.0 before r37163, update to r37163 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2061
CVE-2012-4522
DLA-235-1
RHSA-2013:0129
RHSA-2013:0582
RHSA-2013_0129
SUSE-SU-2013_0435-1

Affected Products

Alt Linux
Red Hat
Ruby
Suse