Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6mch-f8jc-rpmr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.

EPSS

Процентиль: 67%
0.00565
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.

redhat
почти 13 лет назад

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.

nvd
больше 12 лет назад

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.

debian
больше 12 лет назад

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlev ...

oracle-oval
больше 12 лет назад

ELSA-2013-0129: ruby security and bug fix update (MODERATE)

EPSS

Процентиль: 67%
0.00565
Низкий