7.5

CVE-2008-3657

Exploit

The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.

Data is provided by the National Vulnerability Database (NVD)
Ruby-langRuby Version <= 1.8.5
Ruby-langRuby Version1.6.8
Ruby-langRuby Version1.8.0
Ruby-langRuby Version1.8.1
Ruby-langRuby Version1.8.1 Update-9
Ruby-langRuby Version1.8.2
Ruby-langRuby Version1.8.2 Updatepreview2
Ruby-langRuby Version1.8.2 Updatepreview3
Ruby-langRuby Version1.8.2 Updatepreview4
Ruby-langRuby Version1.8.3
Ruby-langRuby Version1.8.3 Updatepreview1
Ruby-langRuby Version1.8.3 Updatepreview2
Ruby-langRuby Version1.8.3 Updatepreview3
Ruby-langRuby Version1.8.4
Ruby-langRuby Version1.8.4 Updatepreview1
Ruby-langRuby Version1.8.4 Updatepreview2
Ruby-langRuby Version1.8.4 Updatepreview3
Ruby-langRuby Version1.8.5 Updatep11
Ruby-langRuby Version1.8.5 Updatep113
Ruby-langRuby Version1.8.5 Updatep115
Ruby-langRuby Version1.8.5 Updatep12
Ruby-langRuby Version1.8.5 Updatep2
Ruby-langRuby Version1.8.5 Updatep35
Ruby-langRuby Version1.8.5 Updatepreview1
Ruby-langRuby Version1.8.5 Updatepreview2
Ruby-langRuby Version1.8.5 Updatepreview3
Ruby-langRuby Version1.8.5 Updatepreview4
Ruby-langRuby Version1.8.5 Updatepreview5
Ruby-langRuby Version1.8.6
Ruby-langRuby Version1.8.6 Updatep110
Ruby-langRuby Version1.8.6 Updatep114
Ruby-langRuby Version1.8.6 Updatepreview1
Ruby-langRuby Version1.8.6 Updatepreview2
Ruby-langRuby Version1.8.6 Updatepreview3
Ruby-langRuby Version1.8.7
Ruby-langRuby Version1.8.7 Updatep17
Ruby-langRuby Version1.8.7 Updatep22
Ruby-langRuby Version1.8.7 Updatep71
Ruby-langRuby Version1.8.7 Updatepreview1
Ruby-langRuby Version1.8.7 Updatepreview2
Ruby-langRuby Version1.8.7 Updatepreview3
Ruby-langRuby Version1.8.7 Updatepreview4
Ruby-langRuby Version1.9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 39.22% 0.972
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.