|
|
| |
|
| |
rubygem-ruby_parser: insecure file creation
| Package(s): | openshift |
CVE #(s): | CVE-2013-0162
|
| Created: | March 1, 2013 |
Updated: | March 6, 2013 |
| Description: |
From the Red Hat advisory:
It was found that ruby_parser from rubygem-ruby_parser created a temporary
file in an insecure way. A local attacker could use this flaw to perform a
symbolic link attack, overwriting arbitrary files accessible to the
application using ruby_parser. |
| Alerts: |
|
( Log in to post comments)
|
|
|