Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7551

Опубликовано: 11 мая 2009
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distributed in Apple OS X before 10.11.4 and other products, mishandles tainting, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string, related to the DL module and the libffi library. NOTE: this vulnerability exists because of a CVE-2009-5147 regression.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ruby193-rubyWill not fix
Red Hat Enterprise Linux 4rubyWill not fix
Red Hat Enterprise Linux 5rubyWill not fix
Red Hat Enterprise Linux 6rubyWill not fix
Red Hat Enterprise Linux 7rubyWill not fix
Red Hat Software Collectionsrh-ruby22-rubyWill not fix
Red Hat Software Collectionsruby193-rubyWill not fix
Red Hat Software Collectionsruby200-rubyWill not fix
Red Hat Subscription Asset Managerruby193-rubyWill not fix
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ruby22-rubyFixedRHSA-2018:058326.03.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-267
https://bugzilla.redhat.com/show_bug.cgi?id=1248935ruby: DL:: dlopen could open a library with tainted library name

EPSS

Процентиль: 38%
0.00166
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 8.4
ubuntu
почти 10 лет назад

The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distributed in Apple OS X before 10.11.4 and other products, mishandles tainting, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string, related to the DL module and the libffi library. NOTE: this vulnerability exists because of a CVE-2009-5147 regression.

CVSS3: 8.4
nvd
почти 10 лет назад

The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distributed in Apple OS X before 10.11.4 and other products, mishandles tainting, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string, related to the DL module and the libffi library. NOTE: this vulnerability exists because of a CVE-2009-5147 regression.

CVSS3: 8.4
debian
почти 10 лет назад

The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby befor ...

CVSS3: 8.4
github
больше 3 лет назад

The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distributed in Apple OS X before 10.11.4 and other products, mishandles tainting, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string, related to the DL module and the libffi library. NOTE: this vulnerability exists because of a CVE-2009-5147 regression.

fstec
почти 10 лет назад

Уязвимость интерпретатора Ruby, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

EPSS

Процентиль: 38%
0.00166
Низкий

2.6 Low

CVSS2