PT-2012-5459 · Ruby+3 · Ruby+3
Peter Bex
·
Published
2012-11-24
·
Updated
2016-10-03
·
CVE-2012-4522
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ruby versions 1.9.3 before patchlevel 286
Ruby versions 2.0.0 before r37163
Description
The issue allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path. This is due to a problem in the
rb get path check function in file.c.Recommendations
For Ruby versions 1.9.3 before patchlevel 286, update to patchlevel 286 or later.
For Ruby versions 2.0.0 before r37163, update to r37163 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Red Hat
Ruby
Suse