Описание
The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.
Отчет
This issue did not affect the versions of ruby as shipped with Red Hat Enterprise Linux 6.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | ruby | Not affected | ||
Red Hat Enterprise Linux 5 | ruby | Fixed | RHSA-2013:0129 | 08.01.2013 |
RHEL 6 Version of OpenShift Enterprise | graphviz | Fixed | RHSA-2013:0582 | 28.02.2013 |
RHEL 6 Version of OpenShift Enterprise | openshift-console | Fixed | RHSA-2013:0582 | 28.02.2013 |
RHEL 6 Version of OpenShift Enterprise | openshift-origin-broker | Fixed | RHSA-2013:0582 | 28.02.2013 |
RHEL 6 Version of OpenShift Enterprise | openshift-origin-broker-util | Fixed | RHSA-2013:0582 | 28.02.2013 |
RHEL 6 Version of OpenShift Enterprise | openshift-origin-cartridge-cron-1.4 | Fixed | RHSA-2013:0582 | 28.02.2013 |
RHEL 6 Version of OpenShift Enterprise | openshift-origin-cartridge-diy-0.1 | Fixed | RHSA-2013:0582 | 28.02.2013 |
RHEL 6 Version of OpenShift Enterprise | openshift-origin-cartridge-haproxy-1.4 | Fixed | RHSA-2013:0582 | 28.02.2013 |
RHEL 6 Version of OpenShift Enterprise | openshift-origin-cartridge-jbosseap-6.0 | Fixed | RHSA-2013:0582 | 28.02.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.
The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.
The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlev ...
The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.
ELSA-2013-0129: ruby security and bug fix update (MODERATE)
EPSS
4.3 Medium
CVSS2