Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4492

Опубликовано: 13 янв. 2010
Источник: ubuntu
Приоритет: negligible
CVSS2: 7.5

Описание

WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

hardy

ignored

end of life
intrepid

ignored

end of life, was needed
jaunty

ignored

end of life
karmic

ignored

end of life
lucid

not-affected

1.8.7.249-2
maverick

not-affected

natty

not-affected

oneiric

not-affected

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

pulled 2010-07-27
hardy

ignored

end of life
intrepid

released

1.9.0.2-7ubuntu1.3
jaunty

released

1.9.0.2-9ubuntu1.2
karmic

released

1.9.0.5-1ubuntu1.2
lucid

released

1.9.0.5-1ubuntu2
maverick

DNE

pulled 2010-07-27
natty

DNE

pulled 2010-07-27
oneiric

DNE

pulled 2010-07-27

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

ignored

end of life
lucid

not-affected

1.9.1.378-1
maverick

not-affected

natty

not-affected

oneiric

not-affected

Показывать по

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 15 лет назад

WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

nvd
больше 15 лет назад

WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

debian
больше 15 лет назад

WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patc ...

github
больше 7 лет назад

WEBrick Improper Input Validation vulnerability

oracle-oval
почти 14 лет назад

ELSA-2011-0909: ruby security update (MODERATE)

7.5 High

CVSS2