CVE-2011-0995: SQL Injection
Published May 13, 2011
·Updated
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
Affected Software
6 affected componentsFixes available
rubygems/sqlite3-ruby<1.2.4
1.2.4
Rubyforge Rubygem-sqlite3<=1.2.3
Rubyforge Rubygem-sqlite3=1.2.0
Rubyforge Rubygem-sqlite3=1.2.1
Rubyforge Rubygem-sqlite3=1.2.2
Novell Suse Linux Enterprise=11-sp1
Event History
May 13, 2011
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
05:05 PM
DescriptionWeaknessAffected Software
Oct 24, 2017
Advisory Published
06:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2011-0995?
CVE-2011-0995 is considered a medium severity vulnerability due to its potential for privilege escalation by local users.
2
How do I fix CVE-2011-0995?
To fix CVE-2011-0995, upgrade the sqlite3-ruby gem to version 1.2.4 or higher.
3
Who is affected by CVE-2011-0995?
CVE-2011-0995 affects local users on systems running vulnerable versions of the rubygem-sqlite3 package prior to 1.2.4.
4
What systems are impacted by CVE-2011-0995?
CVE-2011-0995 impacts SUSE Linux Enterprise 11 SP1 and its use of sqlite3-ruby versions prior to 1.2.4.
5
What files are involved in CVE-2011-0995?
CVE-2011-0995 involves unspecified files that have weak permissions, allowing for privilege escalation.