7.5

CVE-2008-3657

Exploit
The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ruby-lang ≫ Ruby Version <= 1.8.5
Ruby-lang ≫ Ruby Version 1.6.8
Ruby-lang ≫ Ruby Version 1.8.0
Ruby-lang ≫ Ruby Version 1.8.1
Ruby-lang ≫ Ruby Version 1.8.1 Update -9
Ruby-lang ≫ Ruby Version 1.8.2
Ruby-lang ≫ Ruby Version 1.8.2 Update preview2
Ruby-lang ≫ Ruby Version 1.8.2 Update preview3
Ruby-lang ≫ Ruby Version 1.8.2 Update preview4
Ruby-lang ≫ Ruby Version 1.8.3
Ruby-lang ≫ Ruby Version 1.8.3 Update preview1
Ruby-lang ≫ Ruby Version 1.8.3 Update preview2
Ruby-lang ≫ Ruby Version 1.8.3 Update preview3
Ruby-lang ≫ Ruby Version 1.8.4
Ruby-lang ≫ Ruby Version 1.8.4 Update preview1
Ruby-lang ≫ Ruby Version 1.8.4 Update preview2
Ruby-lang ≫ Ruby Version 1.8.4 Update preview3
Ruby-lang ≫ Ruby Version 1.8.5 Update p11
Ruby-lang ≫ Ruby Version 1.8.5 Update p113
Ruby-lang ≫ Ruby Version 1.8.5 Update p115
Ruby-lang ≫ Ruby Version 1.8.5 Update p12
Ruby-lang ≫ Ruby Version 1.8.5 Update p2
Ruby-lang ≫ Ruby Version 1.8.5 Update p35
Ruby-lang ≫ Ruby Version 1.8.5 Update preview1
Ruby-lang ≫ Ruby Version 1.8.5 Update preview2
Ruby-lang ≫ Ruby Version 1.8.5 Update preview3
Ruby-lang ≫ Ruby Version 1.8.5 Update preview4
Ruby-lang ≫ Ruby Version 1.8.5 Update preview5
Ruby-lang ≫ Ruby Version 1.8.6
Ruby-lang ≫ Ruby Version 1.8.6 Update p110
Ruby-lang ≫ Ruby Version 1.8.6 Update p114
Ruby-lang ≫ Ruby Version 1.8.6 Update preview1
Ruby-lang ≫ Ruby Version 1.8.6 Update preview2
Ruby-lang ≫ Ruby Version 1.8.6 Update preview3
Ruby-lang ≫ Ruby Version 1.8.7
Ruby-lang ≫ Ruby Version 1.8.7 Update p17
Ruby-lang ≫ Ruby Version 1.8.7 Update p22
Ruby-lang ≫ Ruby Version 1.8.7 Update p71
Ruby-lang ≫ Ruby Version 1.8.7 Update preview1
Ruby-lang ≫ Ruby Version 1.8.7 Update preview2
Ruby-lang ≫ Ruby Version 1.8.7 Update preview3
Ruby-lang ≫ Ruby Version 1.8.7 Update preview4
Ruby-lang ≫ Ruby Version 1.9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.67% 0.96
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://secunia.com/advisories/35074
Vendor Advisory
http://support.apple.com/kb/HT3549
http://www.us-cert.gov/cas/techalerts/TA09-133A.html
US Government Resource
http://www.vupen.com/english/advisories/2009/1297
Vendor Advisory
http://secunia.com/advisories/32371
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0897.html
http://secunia.com/advisories/33178
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200812-17.xml
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494401
http://secunia.com/advisories/31430
Vendor Advisory
http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/
http://www.vupen.com/english/advisories/2008/2334
Vendor Advisory
http://secunia.com/advisories/32219
Vendor Advisory
https://usn.ubuntu.com/651-1/
http://secunia.com/advisories/31697
Vendor Advisory
http://secunia.com/advisories/32165
Vendor Advisory
http://secunia.com/advisories/32255
Vendor Advisory
http://secunia.com/advisories/32256
Vendor Advisory
http://support.avaya.com/elmodocs2/security/ASA-2008-424.htm
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0264
http://www.debian.org/security/2008/dsa-1651
http://www.debian.org/security/2008/dsa-1652
http://www.securityfocus.com/archive/1/495884/100/0/threaded
http://www.securityfocus.com/bid/30644
Patch
Exploit
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00259.html
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00299.html
http://www.securitytracker.com/id?1020652
https://exchange.xforce.ibmcloud.com/vulnerabilities/44372
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9793