Synced 18 Jun 2026 05:58 UTC Account
← All products

CVE-2010-2489

HIGH severity · CVSS 7.2 · Memory corruption
7.2CVSS HIGH

Summary

Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properly handled when constructing the filenames of the backup files.

Impact & exploitability

Attack vectorLocal
Attack complexityLow
Privileges required
User interaction
Confidentiality impact
Integrity impact
Availability impact
Exploit probability (EPSS)0%

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: http://www.ruby-lang.org/en/news/2010/07/02/ruby-1-9-1-p429-is-released/ ↗