LWN.net Logo

ruby: access restriction bypass

Package(s):ruby1.8 CVE #(s):CVE-2012-4481
Created:October 11, 2012 Updated:March 8, 2013
Description:

From the Ubuntu advisory:

Shugo Maedo and Vit Ondruch discovered that Ruby incorrectly allowed untainted strings to be modified in protective safe levels. An attacker could use this flaw to bypass intended access restrictions. (CVE-2012-4466, CVE-2012-4481)

Alerts:
Ubuntu USN-1603-1 2012-10-10
Mageia MGASA-2012-0294 2012-10-14
Ubuntu USN-1603-2 2012-10-22
Oracle ELSA-2013-0129 2013-01-12
Scientific Linux SL-ruby-20130116 2013-01-16
CentOS CESA-2013:0129 2013-01-09
Red Hat RHSA-2013:0612-01 2013-03-07
Scientific Linux SL-ruby-20130307 2013-03-07
Oracle ELSA-2013-0612 2013-03-08
CentOS CESA-2013:0612 2013-03-09
Mandriva MDVSA-2013:124 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds