CVE-2013-2065: Medium severity suse linux vulnerability
(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native functions, which allows context-dependent attackers to bypass intended $SAFE level restrictions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2065?
CVE-2013-2065 is classified as a medium severity vulnerability due to its potential to allow unauthorized access through evasion of taint checking.
How do I fix CVE-2013-2065?
To fix CVE-2013-2065, upgrade Ruby to versions 1.9.3 patch level 426 or higher or 2.0.0 patch level 195 or higher.
Which versions of Ruby are affected by CVE-2013-2065?
CVE-2013-2065 affects Ruby versions prior to 1.9.3 patch level 426 and 2.0.0 patch level 195.
What does CVE-2013-2065 affect in Ruby?
CVE-2013-2065 affects the security of native functions in Ruby by allowing bypassing of the intended $SAFE level restrictions.
Can CVE-2013-2065 lead to exploitations?
Yes, CVE-2013-2065 can potentially allow context-dependent attackers to exploit applications using affected Ruby versions.