Логотип exploitDog
bind:"BDU:2019-04563" OR bind:"CVE-2017-17790"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2019-04563" OR bind:"CVE-2017-17790"

Количество 8

Количество 8

fstec логотип

BDU:2019-04563

почти 8 лет назад

Уязвимость функции lazy_initialize интерпретатора языка программирования Ruby, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-17790

почти 8 лет назад

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2017-17790

почти 8 лет назад

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2017-17790

почти 8 лет назад

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-17790

почти 8 лет назад

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 us ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-47cm-jxff-w8wg

больше 3 лет назад

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.

CVSS3: 9.8
EPSS: Низкий
oracle-oval логотип

ELSA-2018-0378

больше 7 лет назад

ELSA-2018-0378: ruby security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1570-1

больше 5 лет назад

Security update for ruby2.1

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2019-04563

Уязвимость функции lazy_initialize интерпретатора языка программирования Ruby, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
8%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-17790

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.

CVSS3: 9.8
8%
Низкий
почти 8 лет назад
redhat логотип
CVE-2017-17790

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.

CVSS3: 8.1
8%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-17790

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.

CVSS3: 9.8
8%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-17790

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 us ...

CVSS3: 9.8
8%
Низкий
почти 8 лет назад
github логотип
GHSA-47cm-jxff-w8wg

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.

CVSS3: 9.8
8%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2018-0378

ELSA-2018-0378: ruby security update (IMPORTANT)

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2020:1570-1

Security update for ruby2.1

больше 5 лет назад

Уязвимостей на страницу