CVE-2015-7551: Input Validation

Published Jul 31, 2015
·
Updated

DL::dlopen could open a library with tainted library name even if $SAFE > 0. This vulnerability affects Ruby versions 1.8, 1.9, 2.1, 2.2.

Upstream patch: https://github.com/ruby/ruby/commit/4600cf725a86ce31266153647ae5aa1197b1215b

Additional information and CVE assignment:

http://seclists.org/oss-sec/2015/q3/222

Other sources

The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distributed in Apple OS X before 10.11.4 and other products, mishandles tainting, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string, related to the DL module and the libffi library. NOTE: this vulnerability exists because of a CVE-2009-5147 regression.

Launchpad

Affected Software

19 affected componentsFixes available
debian/ruby1.9.1
debian/ruby2.0
Apple iOS and macOS<=10.11.3
ruby-lang Ruby<=2.0.0-p647
ruby-lang Ruby=2.1.0
ruby-lang Ruby=2.1.1
ruby-lang Ruby=2.1.2
ruby-lang Ruby=2.1.3
ruby-lang Ruby=2.1.4
ruby-lang Ruby=2.1.5
ruby-lang Ruby=2.1.6
ruby-lang Ruby=2.1.7
ruby-lang Ruby=2.2.0
ruby-lang Ruby=2.2.1
ruby-lang Ruby=2.2.2
ruby-lang Ruby=2.2.3
redhat/ruby<2.0.0
2.0.0
redhat/ruby<2.1.8
2.1.8
redhat/ruby<2.2.4
2.2.4

Event History

Jul 31, 2015
Data Sourced
via Red Hat·07:44 AM
DescriptionSeverityAffected Software
Mar 24, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·09:56 PM
Description
Feb 18, 2026
Data Sourced
via Ubuntu·11:45 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2015-7551?

CVE-2015-7551 is classified as a high severity vulnerability due to its potential to allow arbitrary code execution by attackers.

2

What versions of Ruby are affected by CVE-2015-7551?

CVE-2015-7551 affects Ruby versions before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4.

3

How do I fix CVE-2015-7551?

To fix CVE-2015-7551, update Ruby to a version that is 2.0.0-p648 or later, 2.1.8 or later, or 2.2.4 or later.

4

Are macOS versions vulnerable to CVE-2015-7551?

Yes, macOS versions prior to 10.11.4 are susceptible to CVE-2015-7551.

5

Who can exploit CVE-2015-7551?

CVE-2015-7551 can be exploited by context-dependent attackers who can leverage the mishandling of tainting in the Fiddle::Handle implementation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203