6.4

CVE-2013-2065

Exploit
(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native functions, which allows context-dependent attackers to bypass intended $SAFE level restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensuse ≫ Opensuse Version 12.2
Opensuse ≫ Opensuse Version 12.3
Ruby-lang ≫ Ruby Version 1.9
Ruby-lang ≫ Ruby Version 1.9.1
Ruby-lang ≫ Ruby Version 1.9.2
Ruby-lang ≫ Ruby Version 1.9.3
Ruby-lang ≫ Ruby Version 1.9.3 Update p0
Ruby-lang ≫ Ruby Version 1.9.3 Update p125
Ruby-lang ≫ Ruby Version 1.9.3 Update p194
Ruby-lang ≫ Ruby Version 1.9.3 Update p286
Ruby-lang ≫ Ruby Version 1.9.3 Update p383
Ruby-lang ≫ Ruby Version 1.9.3 Update p385
Ruby-lang ≫ Ruby Version 1.9.3 Update p392
Ruby-lang ≫ Ruby Version 2.0
Ruby-lang ≫ Ruby Version 2.0.0
Ruby-lang ≫ Ruby Version 2.0.0 Update p0
Ruby-lang ≫ Ruby Version 2.0.0 Update preview1
Ruby-lang ≫ Ruby Version 2.0.0 Update preview2
Ruby-lang ≫ Ruby Version 2.0.0 Update rc1
Ruby-lang ≫ Ruby Version 2.0.0 Update rc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.51% 0.827
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107064.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107098.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107120.html
http://lists.opensuse.org/opensuse-updates/2013-10/msg00057.html
Vendor Advisory
http://www.ubuntu.com/usn/USN-2035-1
https://puppet.com/security/cve/cve-2013-2065
https://www.ruby-lang.org/en/news/2013/05/14/taint-bypass-dl-fiddle-cve-2013-2065/
Patch
Vendor Advisory
Exploit