Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1005

Опубликовано: 02 мар. 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

hardy

ignored

end of life
karmic

ignored

end of life
lucid

released

1.8.7.249-2ubuntu0.1
maverick

released

1.8.7.299-2ubuntu0.1
natty

released

1.8.7.302-2ubuntu0.1
oneiric

not-affected

1.8.7.352-2
precise

not-affected

upstream

released

1.8.7.334-1

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

hardy

ignored

end of life
karmic

ignored

end of life
lucid

not-affected

maverick

DNE

natty

DNE

oneiric

DNE

precise

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

1.9.3.194-1ubuntu1
hardy

DNE

karmic

ignored

end of life
lucid

not-affected

maverick

ignored

end of life
natty

not-affected

oneiric

not-affected

precise

released

1.9.3.0-1ubuntu2.2
upstream

needs-triage

Показывать по

EPSS

Процентиль: 89%
0.04511
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

nvd
больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

debian
больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through ...

github
около 3 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

oracle-oval
почти 14 лет назад

ELSA-2011-0910: ruby security update (MODERATE)

EPSS

Процентиль: 89%
0.04511
Низкий

5 Medium

CVSS2

Уязвимость CVE-2011-1005