CVE-2006-3694: Medium severity Yukihiro Matsumoto Ruby vulnerability
Published Jul 19, 2006
·Updated
Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations".
Affected Software
3 affected components
Yukihiro Matsumoto Ruby=1.8.4
Yukihiro Matsumoto Ruby=1.8.3
Yukihiro Matsumoto Ruby=1.8.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 19, 2006
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3694?
CVE-2006-3694 is considered to have a moderate severity due to its potential for remote exploitation.
2
How do I fix CVE-2006-3694?
To resolve CVE-2006-3694, upgrade Ruby to version 1.8.5 or later.
3
Which versions of Ruby are affected by CVE-2006-3694?
CVE-2006-3694 affects Ruby versions 1.8.2, 1.8.3, and 1.8.4.
4
What are the attack vectors for CVE-2006-3694?
The vulnerabilities in CVE-2006-3694 can be exploited through the alias function and directory operations.
5
Is CVE-2006-3694 a local or remote vulnerability?
CVE-2006-3694 is a remote vulnerability that allows attackers to bypass certain safety checks.