Lucene search

K
cve[email protected]CVE-2008-3655
HistoryAug 13, 2008 - 1:41 a.m.

CVE-2008-3655

2008-08-1301:41:00
CWE-264
web.nvd.nist.gov
43
cve-2008-3655
ruby
access restrictions
safe levels
security vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

High

EPSS

0.356

Percentile

97.2%

Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended access restrictions via (1) untrace_var, (2) $PROGRAM_NAME, and (3) syslog at safe level 4, and (4) insecure methods at safe levels 1 through 3.

Affected configurations

NVD
Node
ruby-langrubyRange1.8.5
OR
ruby-langrubyMatch1.6.8
OR
ruby-langrubyMatch1.8.0
OR
ruby-langrubyMatch1.8.1
OR
ruby-langrubyMatch1.8.1-9
OR
ruby-langrubyMatch1.8.2
OR
ruby-langrubyMatch1.8.2preview2
OR
ruby-langrubyMatch1.8.2preview3
OR
ruby-langrubyMatch1.8.2preview4
OR
ruby-langrubyMatch1.8.3
OR
ruby-langrubyMatch1.8.3preview1
OR
ruby-langrubyMatch1.8.3preview2
OR
ruby-langrubyMatch1.8.3preview3
OR
ruby-langrubyMatch1.8.4
OR
ruby-langrubyMatch1.8.4preview1
OR
ruby-langrubyMatch1.8.4preview2
OR
ruby-langrubyMatch1.8.4preview3
OR
ruby-langrubyMatch1.8.5p11
OR
ruby-langrubyMatch1.8.5p113
OR
ruby-langrubyMatch1.8.5p115
OR
ruby-langrubyMatch1.8.5p12
OR
ruby-langrubyMatch1.8.5p2
OR
ruby-langrubyMatch1.8.5p35
OR
ruby-langrubyMatch1.8.5preview1
OR
ruby-langrubyMatch1.8.5preview2
OR
ruby-langrubyMatch1.8.5preview3
OR
ruby-langrubyMatch1.8.5preview4
OR
ruby-langrubyMatch1.8.5preview5
OR
ruby-langrubyMatch1.8.6
OR
ruby-langrubyMatch1.8.6p110
OR
ruby-langrubyMatch1.8.6p111
OR
ruby-langrubyMatch1.8.6p114
OR
ruby-langrubyMatch1.8.6p230
OR
ruby-langrubyMatch1.8.6p286
OR
ruby-langrubyMatch1.8.6p36
OR
ruby-langrubyMatch1.8.6preview1
OR
ruby-langrubyMatch1.8.6preview2
OR
ruby-langrubyMatch1.8.6preview3
OR
ruby-langrubyMatch1.8.7
OR
ruby-langrubyMatch1.8.7p17
OR
ruby-langrubyMatch1.8.7p22
OR
ruby-langrubyMatch1.8.7p71
OR
ruby-langrubyMatch1.8.7preview1
OR
ruby-langrubyMatch1.8.7preview2
OR
ruby-langrubyMatch1.8.7preview3
OR
ruby-langrubyMatch1.8.7preview4
OR
ruby-langrubyMatch1.9.0
VendorProductVersionCPE
ruby-langruby1.8.7cpe:/a:ruby-lang:ruby:1.8.7:preview3::
ruby-langruby1.8.5cpe:/a:ruby-lang:ruby:1.8.5:p115::
ruby-langruby1.8.5cpe:/a:ruby-lang:ruby:1.8.5:p12::
ruby-langruby1.8.6cpe:/a:ruby-lang:ruby:1.8.6:p36::
ruby-langruby1.8.2cpe:/a:ruby-lang:ruby:1.8.2:::
ruby-langruby1.8.7cpe:/a:ruby-lang:ruby:1.8.7:p22::
ruby-langruby1.8.2cpe:/a:ruby-lang:ruby:1.8.2:preview2::
ruby-langruby1.8.2cpe:/a:ruby-lang:ruby:1.8.2:preview4::
ruby-langruby1.8.3cpe:/a:ruby-lang:ruby:1.8.3:preview1::
ruby-langruby1.8.6cpe:/a:ruby-lang:ruby:1.8.6:preview1::
Rows per page:
1-10 of 471

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

High

EPSS

0.356

Percentile

97.2%