LWN.net Logo

ruby: unintended file creation

Package(s):ruby CVE #(s):CVE-2012-4522
Created:October 22, 2012 Updated:January 17, 2013
Description: From the Red Hat bugzilla:

An upstream Ruby security notice indicated that ruby suffered from a flaw where unintended files could be created if they contained a NUL characer in the file path or name. Certain methods like IO#open did not check the filename passed to them, and just passed those strings to lower layer routines, which could lead to unintentional files being created

Alerts:
Fedora FEDORA-2012-16086 2012-10-22
Ubuntu USN-1614-1 2012-10-22
Oracle ELSA-2013-0129 2013-01-12
Scientific Linux SL-ruby-20130116 2013-01-16
CentOS CESA-2013:0129 2013-01-09
Red Hat RHSA-2013:0582-01 2013-02-28
openSUSE openSUSE-SU-2013:0376-1 2013-03-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds