9.1

CVE-2018-8780

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ruby-lang ≫ Ruby Version < 2.2.10
Ruby-lang ≫ Ruby Version >= 2.3.0 < 2.3.7
Ruby-lang ≫ Ruby Version >= 2.4.0 < 2.4.4
Ruby-lang ≫ Ruby Version >= 2.5.0 < 2.5.1
Ruby-lang ≫ Ruby Version 2.6.0 Update preview1
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.9% 0.951
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html
Third Party Advisory
Mailing List
http://www.securitytracker.com/id/1042004
Third Party Advisory
VDB Entry
https://www.debian.org/security/2018/dsa-4259
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html
https://access.redhat.com/errata/RHSA-2018:3729
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3730
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3731
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2028
https://access.redhat.com/errata/RHSA-2020:0542
https://access.redhat.com/errata/RHSA-2020:0591
https://access.redhat.com/errata/RHSA-2020:0663
https://lists.debian.org/debian-lts-announce/2018/04/msg00023.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2018/04/msg00024.html
Third Party Advisory
Mailing List
https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-2-10-released/
Patch
Vendor Advisory
https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-3-7-released/
Patch
Vendor Advisory
https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-4-4-released/
Patch
Vendor Advisory
https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-5-1-released/
Patch
Vendor Advisory
https://usn.ubuntu.com/3626-1/
Third Party Advisory
http://www.securityfocus.com/bid/103739
Third Party Advisory
VDB Entry
https://www.ruby-lang.org/en/news/2018/03/28/poisoned-nul-byte-dir-cve-2018-8780/
Vendor Advisory