PT-2014-4891 · Ruby+2 · Ruby+2

Emboss

·

Published

2014-04-24

·

Updated

2025-09-29

·

CVE-2014-2734

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ruby versions 2.x
Description The issue concerns the openssl extension in Ruby, which does not properly maintain the state of process memory after a file is reopened. This allows remote attackers to spoof signatures within the context of a Ruby script that attempts signature verification after performing a certain sequence of filesystem operations. The issue has been disputed by the Ruby OpenSSL team and third parties, who state that the original demonstration contains errors and redundant or unnecessarily-complex code.
Recommendations For Ruby version 2.x, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2016-2061
CVE-2014-2734

Affected Products

Alt Linux
Openssl
Ruby