PT-2013-1677 · Ruby+2 · Ruby+2
Shugo Maedo
+1
·
Published
2013-04-25
·
Updated
2016-10-03
·
CVE-2012-4466
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ruby versions 1.8.7 before patchlevel 371
Ruby versions 1.9.3 before patchlevel 286
Ruby versions 2.0 before revision r37068
Description
The issue allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the
name err mesg to str API function. This function marks the string as tainted.Recommendations
For Ruby version 1.8.7, update to patchlevel 371 or later.
For Ruby version 1.9.3, update to patchlevel 286 or later.
For Ruby version 2.0, update to revision r37068 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ruby
Suse