|
[Japanese]
|
JVNDB-2006-000392
|
Ruby contains a vulnerability that prevents safe level 4 from functioning as a sandbox.
|
Safe level is a security model provided by Ruby language that limits the operation of untrusted objects. A vulnerability that allows an attacker to bypass the safe level restrictions and execute inaccessible methods (ex. destructive methods) was confirmed.
|
Base Metrics:
1.2 (Low)
[IPA Score]
- Access Vector: Local
- Access Complexity: High
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
|
Ruby
- Ruby 1.8.4-20060516 and earlier Snapshot versions
MIRACLE LINUX CORPORATION
- MIRACLE LINUX V3.0
- MIRACLE LINUX V3.0 for x86-64
- MIRACLE LINUX V4.0
- MIRACLE LINUX V4.0 for x86-64
Red Hat, Inc.
- Red Hat Enterprise Linux AS (v.2.1)
- Red Hat Enterprise Linux AS (v.3)
- Red Hat Enterprise Linux AS (v.4)
- Red Hat Enterprise Linux ES (v.2.1)
- Red Hat Enterprise Linux ES (v.3)
- Red Hat Enterprise Linux ES (v.4)
- Red Hat Enterprise Linux WS (v.2.1)
- Red Hat Enterprise Linux WS (v.3)
- Red Hat Enterprise Linux WS (v.4)
|
|
An attacker may be able to bypass the security model of a server application and change the status of a untained object.
|
|
Ruby
MIRACLE LINUX CORPORATION
Red Hat, Inc.
|
- No Mapping(CWE-DesignError) [NVD Evaluation]
|
- CVE-2006-3694
|
- JVN : JVN#13947696
- National Vulnerability Database (NVD) : CVE-2006-3694
- Secunia Advisory : SA21009
- SecurityFocus : 18944
- FrSIRT Advisories : FrSIRT/ADV-2006-2760
|
[2008/05/21]
Web page published
|