First published: Mon Jun 12 2017(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ruby1.8 | ||
debian/ruby1.9.1 | ||
debian/ruby2.1 | ||
Ruby | <=2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9096 is considered a medium severity vulnerability due to its potential for SMTP command injection.
To fix CVE-2015-9096, update Ruby to version 2.4.0 or later.
CVE-2015-9096 affects Ruby versions prior to 2.4.0 including ruby1.8, ruby1.9.1, and ruby2.1.
CVE-2015-9096 is an SMTP command injection vulnerability.
There is no known workaround for CVE-2015-9096; the recommended solution is to upgrade Ruby.