Lucene search

K
rubygemsRubySecRUBY:RUBY-2006-3694
HistoryJul 20, 2006 - 8:00 p.m.

ruby1.8 vulnerability

2006-07-2020:00:00
RubySec
www.ubuntu.com
8

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow
remote attackers to bypass safe level checks via unspecified
vectors involving (1) the alias function and
(2) directory operations.

Affected configurations

Vulners
Node
rubyrubyRange1.8.5
VendorProductVersionCPE
rubyruby*cpe:2.3:a:ruby:ruby:*:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N