|
|
| |
|
| |
ruby: unintended file creation
| Package(s): | ruby |
CVE #(s): | CVE-2012-4522
|
| Created: | October 22, 2012 |
Updated: | January 17, 2013 |
| Description: |
From the Red Hat bugzilla:
An upstream Ruby security notice indicated that ruby suffered from a flaw where unintended files could be created if they contained a NUL characer in the file path or name. Certain methods like IO#open did not check the filename passed to them, and just passed those strings to lower layer routines, which could lead to unintentional files being created |
| Alerts: |
|
( Log in to post comments)
|
|
|