5

CVE-2011-2686

Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900.  NOTE: this issue exists because of a regression during Ruby 1.8.6 development.

Data is provided by the National Vulnerability Database (NVD)
Ruby-langRuby Version <= 1.8.7-334
Ruby-langRuby Version1.8.7 Updatep22
Ruby-langRuby Version1.8.7 Updatep71
Ruby-langRuby Version1.8.7 Updatep72
Ruby-langRuby Version1.8.7-160
Ruby-langRuby Version1.8.7-173
Ruby-langRuby Version1.8.7-248
Ruby-langRuby Version1.8.7-249
Ruby-langRuby Version1.8.7-299
Ruby-langRuby Version1.8.7-302
Ruby-langRuby Version1.8.7-330
Ruby-langRuby Version1.8.7-p21
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.8% 0.733
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N