Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-5147

Опубликовано: 29 мар. 2017
Источник: debian
EPSS Средний

Описание

DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby1.8removedpackage
ruby1.8no-dsawheezypackage
ruby1.9.1removedpackage
ruby1.9.1no-dsawheezypackage
ruby2.0removedpackage
ruby2.1removedpackage
ruby2.1fixed2.1.5-2+deb8u3jessiepackage
ruby2.2not-affectedpackage

Примечания

  • https://github.com/ruby/ruby/commit/4600cf725a86ce31266153647ae5aa1197b1215b

  • Although the is upstream commit mentioned, the corresponding change does not

  • seem to be contained in e.g. latest 1.9.1 and 2.1. E.g.

  • https://sources.debian.org/src/ruby2.1/2.1.5-4/ext/dl/handle.c/#L120 does not

  • contain the change.

  • In https://github.com/ruby/ruby/commit/07308c4d30b8c5260e5366c8eed2abf054d86fe7

  • Discussion http://seclists.org/oss-sec/2015/q3/220

  • DL has been replaced in 2.2 with Fiddle which has the same problem according to maintainer.

EPSS

Процентиль: 98%
0.52002
Средний

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 8 лет назад

DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.

redhat
больше 16 лет назад

DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.

CVSS3: 7.3
nvd
больше 8 лет назад

DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.

CVSS3: 7.3
github
больше 3 лет назад

DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.

EPSS

Процентиль: 98%
0.52002
Средний