CVE-2011-1005
MEDIUM severity · CVSS 5 · CWE-264
5CVSS MEDIUM
Summary
The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impactNone
Exploit probability (EPSS)3%
AV:N/AC:L/Au:N/C:N/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054422.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054436.html
- http://osvdb.org/70957
- http://secunia.com/advisories/43420
- http://secunia.com/advisories/43573
- http://support.apple.com/kb/HT5281
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:097