Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properly handled when constructing the filenames of the backup files.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:16
Type | Values Removed | Values Added |
---|---|---|
References | () http://osdir.com/ml/ruby-talk/2010-07/msg00095.html - | |
References | () http://secunia.com/advisories/40442 - Vendor Advisory | |
References | () http://svn.ruby-lang.org/repos/ruby/tags/v1_9_1_429/ChangeLog - | |
References | () http://svn.ruby-lang.org/repos/ruby/tags/v1_9_2_rc1/ChangeLog - | |
References | () http://www.openwall.com/lists/oss-security/2010/07/02/1 - | |
References | () http://www.openwall.com/lists/oss-security/2010/07/02/10 - | |
References | () http://www.osvdb.org/66040 - | |
References | () http://www.ruby-lang.org/en/news/2010/07/02/ruby-1-9-1-p429-is-released/ - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/41321 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/60135 - |
Information
Published : 2010-07-12 13:27
Updated : 2024-11-21 01:16
NVD link : CVE-2010-2489
Mitre link : CVE-2010-2489
CVE.ORG link : CVE-2010-2489
JSON object : View
Products Affected
microsoft
- windows
ruby-lang
- ruby
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer