CVE-2005-2337: High severity Yukihiro Matsumoto Ruby vulnerability
Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2337?
CVE-2005-2337 is considered a high severity vulnerability due to its potential for code execution by attackers.
How do I fix CVE-2005-2337?
To fix CVE-2005-2337, upgrade Ruby to a patched version 1.8.3 or later.
Which versions of Ruby are affected by CVE-2005-2337?
CVE-2005-2337 affects Ruby versions 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01.
What type of attack does CVE-2005-2337 allow?
CVE-2005-2337 allows attackers to bypass safe level and taint flag protections, enabling disallowed code execution.
How can I determine if my Ruby installation is vulnerable to CVE-2005-2337?
Check your Ruby version against the affected versions listed in CVE-2005-2337 to determine if your installation is vulnerable.