[FREEBSD:3B50881D-1860-4721-AAB1-503290E23F6C] Ruby -- unsafe tainted string vulnerability
Severity
High
Affected Packages
1
CVEs
1
Ruby developer reports:
There is an unsafe tainted string vulnerability in Fiddle and DL.
This issue was originally reported and fixed with CVE-2009-5147 in
DL, but reappeared after DL was reimplemented using Fiddle and
libffi.
And, about DL, CVE-2009-5147 was fixed at Ruby 1.9.1, but not
fixed at other branches, then rubies which bundled DL except Ruby
1.9.1 are still vulnerable.
Package | Affected Version |
---|---|
pkg:freebsd/ruby | < 2.0.0.648,1 |
- ID
- FREEBSD:3B50881D-1860-4721-AAB1-503290E23F6C
- Severity
- high
- Severity from
- CVE-2015-7551
- URL
- http://vuxml.freebsd.org/freebsd/3b50881d-1860-4721-aab1-503290e23f6c.html
- Published
-
2015-12-16T00:00:00
(8 years ago) - Modified
-
2015-12-23T00:00:00
(8 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | https://www.ruby-lang.org/en/news/2015/12/16/unsafe-tainted-string-usage-in-fiddle-and-dl-cve-2015-7551/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:freebsd/ruby | ruby | < 2.0.0.648,1 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |