Описание
The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 1.8.4-1ubuntu1.6 |
devel | not-affected | 1.8.7.72-1 |
feisty | released | 1.8.5-4ubuntu2.3 |
gutsy | released | 1.8.6.36-1ubuntu3.3 |
hardy | released | 1.8.6.111-2ubuntu1.2 |
intrepid | not-affected | 1.8.7.72-1 |
jaunty | not-affected | 1.8.7.72-1 |
karmic | not-affected | 1.8.7.72-1 |
lucid | not-affected | 1.8.7.72-1 |
maverick | not-affected | 1.8.7.72-1 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | ignored | end of life |
devel | DNE | pulled 2010-07-27 |
feisty | ignored | end of life, was needed |
gutsy | ignored | end of life, was needed |
hardy | ignored | end of life |
intrepid | released | 1.9.0.2-7 |
jaunty | released | 1.9.0.2-7 |
karmic | released | 1.9.0.2-7 |
lucid | released | 1.9.0.2-7 |
maverick | DNE | pulled 2010-07-27 |
Показывать по
EPSS
7.5 High
CVSS2
Связанные уязвимости
The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.
The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.
The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8 ...
The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации
EPSS
7.5 High
CVSS2