Lucene search

K
rubygemsRubySecRUBY:NORI-2013-0285-90196
HistoryJan 09, 2013 - 8:00 p.m.

Ruby Gem nori Parameter Parsing Remote Code Execution

2013-01-0920:00:00
RubySec
rubysec.com
26

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.973 High

EPSS

Percentile

99.9%

The Ruby Gem nori has a parameter parsing error that may allow an attacker
to execute arbitrary code. This vulnerability has to do with type casting
during parsing, and is related to CVE-2013-0156.

CPENameOperatorVersion
norile1.0.2
norige1.1.0
norile1.1.3
norige1.2.0
norilt2.0.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.973 High

EPSS

Percentile

99.9%