CVE-2017-10784
Summary
| CVE | CVE-2017-10784 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-19 17:29:00 UTC |
| Updated | 2018-10-31 10:29:00 UTC |
| Description | The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Ruby 2.2.8 Released |
CONFIRM |
www.ruby-lang.org |
Patch, Vendor Advisory |
| CVE-2017-10784: Escape sequence injection vulnerability in the Basic authentication of WEBrick |
CONFIRM |
www.ruby-lang.org |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [SECURITY] [DLA 1421-1] ruby2.1 security update |
MLIST |
lists.debian.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Apple macOS/OS X Multiple Remote Code Execution, Denial of Service, and Information Disclosure Attacks and Local Privilege Escalation Attacks - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| Debian -- Security Information -- DSA-4031-1 ruby2.3 |
DEBIAN |
www.debian.org |
|
| Ruby: Multiple vulnerabilities (GLSA 201710-18) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Ruby Multiple Flaws Let Remote Users Inject Log Data, Deny Service, and Obtain Potentially Sensitive Information from the Heap - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Ruby CVE-2017-10784 Security Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| USN-3685-1: Ruby vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| USN-3528-1: Ruby vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Ruby 2.3.5 Released |
CONFIRM |
www.ruby-lang.org |
Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500608 Alpine Linux Security Update for ruby
- 504368 Alpine Linux Security Update for ruby
- 710368 Gentoo Linux Ruby Multiple Vulnerabilities (GLSA 201710-18)