First published: Mon May 11 2009(Updated: )
DL::dlopen could open a library with tainted library name even if $SAFE > 0. This vulnerability affects Ruby versions 1.8, 1.9, 2.1, 2.2. Upstream patch: <a href="https://github.com/ruby/ruby/commit/4600cf725a86ce31266153647ae5aa1197b1215b">https://github.com/ruby/ruby/commit/4600cf725a86ce31266153647ae5aa1197b1215b</a> Additional information and CVE assignment: <a href="http://seclists.org/oss-sec/2015/q3/222">http://seclists.org/oss-sec/2015/q3/222</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ruby-lang Ruby | =1.8.0 | |
Ruby-lang Ruby | =1.9.0 | |
Ruby-lang Ruby | =1.9.2 | |
Ruby-lang Ruby | =1.9.3 | |
Ruby-lang Ruby | =2.0.0 | |
Ruby-lang Ruby | =2.0.0-p195 | |
Ruby-lang Ruby | =2.0.0-p247 | |
Ruby-lang Ruby | =2.0.0-p353 | |
Ruby-lang Ruby | =2.0.0-p481 | |
Ruby-lang Ruby | =2.0.0-p576 | |
Ruby-lang Ruby | =2.0.0-p594 | |
Ruby-lang Ruby | =2.0.0-p598 | |
Ruby-lang Ruby | =2.0.0-p643 | |
Ruby-lang Ruby | =2.0.0-p645 | |
Ruby-lang Ruby | =2.0.0-p647 | |
Ruby-lang Ruby | =2.1.0 | |
Ruby-lang Ruby | =2.1.1 | |
Ruby-lang Ruby | =2.1.2 | |
Ruby-lang Ruby | =2.1.3 | |
Ruby-lang Ruby | =2.1.4 | |
Ruby-lang Ruby | =2.1.5 | |
Ruby-lang Ruby | =2.1.6 | |
Ruby-lang Ruby | =2.1.7 | |
debian/ruby1.8 | ||
debian/ruby1.9.1 | ||
debian/ruby2.0 | ||
redhat/rh-ruby22-ruby | <0:2.2.9-19.el6 | 0:2.2.9-19.el6 |
redhat/rh-ruby22-ruby | <0:2.2.9-19.el7 | 0:2.2.9-19.el7 |
redhat/ruby | <2.0.0 | 2.0.0 |
redhat/ruby | <2.1.8 | 2.1.8 |
redhat/ruby | <2.2.4 | 2.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.