LWN.net Logo

ruby: arbitrary code execution

Package(s):ruby1.9 CVE #(s):CVE-2009-4124
Created:February 16, 2010 Updated:February 17, 2010
Description: From the Ubuntu advisory:

Emmanouel Kellinis discovered that Ruby did not properly handle certain string operations. An attacker could exploit this issue and possibly execute arbitrary code with application privileges.

Alerts:
Ubuntu USN-900-1 2010-02-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds