PT-2013-1677 · Ruby+2 · Ruby+2

Shugo Maedo

+1

·

Published

2013-04-25

·

Updated

2016-10-03

·

CVE-2012-4466

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ruby versions 1.8.7 before patchlevel 371 Ruby versions 1.9.3 before patchlevel 286 Ruby versions 2.0 before revision r37068
Description The issue allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the name err mesg to str API function. This function marks the string as tainted.
Recommendations For Ruby version 1.8.7, update to patchlevel 371 or later. For Ruby version 1.9.3, update to patchlevel 286 or later. For Ruby version 2.0, update to revision r37068 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2061
CVE-2012-4466
RHSA-2013:0582

Affected Products

Alt Linux
Ruby
Suse