5

CVE-2012-4466

Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the name_err_mesg_to_str API function, which marks the string as tainted, a different vulnerability than CVE-2011-1005.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ruby-lang ≫ Ruby Version 1.8.7
Ruby-lang ≫ Ruby Version 1.8.7 Update p160
Ruby-lang ≫ Ruby Version 1.8.7 Update p17
Ruby-lang ≫ Ruby Version 1.8.7 Update p173
Ruby-lang ≫ Ruby Version 1.8.7 Update p174
Ruby-lang ≫ Ruby Version 1.8.7 Update p22
Ruby-lang ≫ Ruby Version 1.8.7 Update p248
Ruby-lang ≫ Ruby Version 1.8.7 Update p249
Ruby-lang ≫ Ruby Version 1.8.7 Update p299
Ruby-lang ≫ Ruby Version 1.8.7 Update p301
Ruby-lang ≫ Ruby Version 1.8.7 Update p302
Ruby-lang ≫ Ruby Version 1.8.7 Update p330
Ruby-lang ≫ Ruby Version 1.8.7 Update p334
Ruby-lang ≫ Ruby Version 1.8.7 Update p352
Ruby-lang ≫ Ruby Version 1.8.7 Update p357
Ruby-lang ≫ Ruby Version 1.8.7 Update p358
Ruby-lang ≫ Ruby Version 1.8.7 Update p370
Ruby-lang ≫ Ruby Version 1.8.7 Update p71
Ruby-lang ≫ Ruby Version 1.8.7 Update p72
Ruby-lang ≫ Ruby Version 1.8.7 Update preview1
Ruby-lang ≫ Ruby Version 1.8.7 Update preview2
Ruby-lang ≫ Ruby Version 1.8.7 Update preview3
Ruby-lang ≫ Ruby Version 1.8.7 Update preview4
Ruby-lang ≫ Ruby Version 1.9.3
Ruby-lang ≫ Ruby Version 1.9.3 Update p0
Ruby-lang ≫ Ruby Version 1.9.3 Update p125
Ruby-lang ≫ Ruby Version 1.9.3 Update p194
Ruby-lang ≫ Ruby Version 2.0
Ruby-lang ≫ Ruby Version 2.0.0
Ruby-lang ≫ Ruby Version 2.0.0 Update p0
Ruby-lang ≫ Ruby Version 2.0.0 Update preview1
Ruby-lang ≫ Ruby Version 2.0.0 Update preview2
Ruby-lang ≫ Ruby Version 2.0.0 Update rc1
Ruby-lang ≫ Ruby Version 2.0.0 Update rc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.62% 0.835
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.mandriva.com/security/advisories?name=MDVSA-2013:124
http://lists.fedoraproject.org/pipermail/package-announce/2012-October/089554.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-October/089887.html
http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=37068
http://www.openwall.com/lists/oss-security/2012/10/02/4
http://www.openwall.com/lists/oss-security/2012/10/03/9
http://www.ruby-lang.org/en/news/2012/10/12/cve-2012-4464-cve-2012-4466/
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=862614
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0294