OSVDB ID: 27145

Title: Ruby Directory Operations Safe Level Security Bypass

Info

Disclosure

Jul 11, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Ruby contains a flaw that may allow a malicious user to bypass Safe Level restrictions. The issue is triggered when improper validation of the 'alias' function occurs. It is possible that the flaw may allow malicious code execution resulting in a loss of confidentiality, integrity.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 1.8.5 or higher, as it has been reported to fix this vulnerability. A patch is also available from various Linux vendors.

Products

Ruby

Ruby

1.8.4
1.8.3
1.8.2x
1.8.1
1.6
1.6.8
1.6.7

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/27145