CVE-2013-2065
(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for nat… (CVE-2013-2065)
noneEPSS 2.5%
Description
Metrics
Severity
none
50.24
no public PoC known
83.8 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2013-11-02 19:00 UTC
—
Affected operating systems
os
opensuse / opensuse12.2
os
opensuse / opensuse12.3
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
ruby-lang
ruby
References & sources
- https://puppet.com/security/cve/cve-2013-2065x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107064.htmlvendor-advisoryx_refsource_FEDORA
- http://www.ubuntu.com/usn/USN-2035-1vendor-advisoryx_refsource_UBUNTU
- https://www.ruby-lang.org/en/news/2013/05/14/taint-bypass-dl-fiddle-cve-2013-2065/x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107098.htmlvendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-updates/2013-10/msg00057.htmlvendor-advisoryx_refsource_SUSE
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107120.htmlvendor-advisoryx_refsource_FEDORA
IDCVE-2013-2065