Description
DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: Low
Availability: Low
Affected Packages1 packages
🔴Vulnerability Details
4GHSAGHSA-mmq8-m72q-qgm4: DL::dlopen in Ruby 1↗2022-05-02 ▶ OSVruby1.9.1, ruby2.0, ruby2.3 vulnerabilities↗2017-07-25 ▶ CVEListCVE-2009-5147: DL::dlopen in Ruby 1↗2017-03-29 ▶ OSVCVE-2009-5147: DL::dlopen in Ruby 1↗2017-03-29 ▶ 📋Vendor Advisories
3UbuntuRuby vulnerabilities↗2017-07-25 ▶ Red Hatruby: DL:: dlopen could open a library with tainted library name↗2009-05-11 ▶ Red Hatruby: DL:: dlopen could open a library with tainted library name↗2009-05-11 ▶ 💬Community
2BugzillaCVE-2009-5147 CVE-2015-7551 ruby: DL::dlopen could open a library with tainted library name↗2015-07-31 ▶ BugzillaCVE-2009-5147 CVE-2015-7551 ruby: DL::dlopen could open a library with tainted library name [fedora-all]↗2015-07-31 ▶