Lucene search

K
ubuntuUbuntuUSN-805-1
HistoryJul 20, 2009 - 12:00 a.m.

Ruby vulnerabilities

2009-07-2000:00:00
ubuntu.com
47

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.025

Percentile

90.2%

Releases

  • Ubuntu 9.04
  • Ubuntu 8.10
  • Ubuntu 8.04
  • Ubuntu 6.06

Packages

  • ruby1.8 -
  • ruby1.9 -

Details

It was discovered that Ruby did not properly validate certificates. An
attacker could exploit this and present invalid or revoked X.509
certificates. (CVE-2009-0642)

It was discovered that Ruby did not properly handle string arguments that
represent large numbers. An attacker could exploit this and cause a denial
of service. (CVE-2009-1904)

OSVersionArchitecturePackageVersionFilename
Ubuntu9.04noarchruby1.8<Β 1.8.7.72-3ubuntu0.1UNKNOWN
Ubuntu9.04noarchlibdbm-ruby1.8<Β 1.8.7.72-3ubuntu0.1UNKNOWN
Ubuntu9.04noarchlibgdbm-ruby1.8<Β 1.8.7.72-3ubuntu0.1UNKNOWN
Ubuntu9.04noarchlibopenssl-ruby1.8<Β 1.8.7.72-3ubuntu0.1UNKNOWN
Ubuntu9.04noarchlibreadline-ruby1.8<Β 1.8.7.72-3ubuntu0.1UNKNOWN
Ubuntu9.04noarchlibruby1.8<Β 1.8.7.72-3ubuntu0.1UNKNOWN
Ubuntu9.04noarchlibruby1.8-dbg<Β 1.8.7.72-3ubuntu0.1UNKNOWN
Ubuntu9.04noarchlibtcltk-ruby1.8<Β 1.8.7.72-3ubuntu0.1UNKNOWN
Ubuntu9.04noarchruby1.8-dev<Β 1.8.7.72-3ubuntu0.1UNKNOWN
Ubuntu9.04noarchruby1.9<Β 1.9.0.2-9ubuntu1.1UNKNOWN
Rows per page:
1-10 of 541

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.025

Percentile

90.2%