PT-2014-4891 · Ruby+2 · Ruby+2
Emboss
·
Published
2014-04-24
·
Updated
2025-09-29
·
CVE-2014-2734
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ruby versions 2.x
Description
The issue concerns the openssl extension in Ruby, which does not properly maintain the state of process memory after a file is reopened. This allows remote attackers to spoof signatures within the context of a Ruby script that attempts signature verification after performing a certain sequence of filesystem operations. The issue has been disputed by the Ruby OpenSSL team and third parties, who state that the original demonstration contains errors and redundant or unnecessarily-complex code.
Recommendations
For Ruby version 2.x, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Openssl
Ruby