OSVDB ID: 27144

Title: Ruby alias Function Safe Level Security Bypass

Info

Disclosure

Jul 11, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Ruby contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered due to an unspecified error in the handling of the "alias" functionality. No further details have been provided.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Other
Impact: Loss of Confidentiality
Exploit: Exploit Unknown

Solution

Upgrade to version 1.8.5, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds. This vulnerability has also been fixed in a snapshot version in the CVS repository.

Products

Yukihiro Matsumoto

Ruby

1.8.4

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/27144