Lucene search

K
rubygemsRubySecRUBY:RUBY_PARSER-2013-0162-90561
HistoryFeb 20, 2013 - 8:00 p.m.

CVE-2013-0162 rubygem-ruby_parser: incorrect temporary file usage

2013-02-2020:00:00
RubySec
rubysec.com
3

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

0.0004 Low

EPSS

Percentile

5.1%

The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser
gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via
a symlink attack on a temporary file with a predictable name in /tmp.

CPENameOperatorVersion
ruby_parserlt3.1.2

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

0.0004 Low

EPSS

Percentile

5.1%