5

CVE-2012-4466

Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the name_err_mesg_to_str API function, which marks the string as tainted, a different vulnerability than CVE-2011-1005.

Data is provided by the National Vulnerability Database (NVD)
Ruby-langRuby Version1.8.7
Ruby-langRuby Version1.8.7 Updatep160
Ruby-langRuby Version1.8.7 Updatep17
Ruby-langRuby Version1.8.7 Updatep173
Ruby-langRuby Version1.8.7 Updatep174
Ruby-langRuby Version1.8.7 Updatep22
Ruby-langRuby Version1.8.7 Updatep248
Ruby-langRuby Version1.8.7 Updatep249
Ruby-langRuby Version1.8.7 Updatep299
Ruby-langRuby Version1.8.7 Updatep301
Ruby-langRuby Version1.8.7 Updatep302
Ruby-langRuby Version1.8.7 Updatep330
Ruby-langRuby Version1.8.7 Updatep334
Ruby-langRuby Version1.8.7 Updatep352
Ruby-langRuby Version1.8.7 Updatep357
Ruby-langRuby Version1.8.7 Updatep358
Ruby-langRuby Version1.8.7 Updatep370
Ruby-langRuby Version1.8.7 Updatep71
Ruby-langRuby Version1.8.7 Updatep72
Ruby-langRuby Version1.8.7 Updatepreview1
Ruby-langRuby Version1.8.7 Updatepreview2
Ruby-langRuby Version1.8.7 Updatepreview3
Ruby-langRuby Version1.8.7 Updatepreview4
Ruby-langRuby Version1.9.3
Ruby-langRuby Version1.9.3 Updatep0
Ruby-langRuby Version1.9.3 Updatep125
Ruby-langRuby Version1.9.3 Updatep194
Ruby-langRuby Version2.0
Ruby-langRuby Version2.0.0
Ruby-langRuby Version2.0.0 Updatep0
Ruby-langRuby Version2.0.0 Updatepreview1
Ruby-langRuby Version2.0.0 Updatepreview2
Ruby-langRuby Version2.0.0 Updaterc1
Ruby-langRuby Version2.0.0 Updaterc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.52% 0.807
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N