Yukihiro Matsumoto Ruby XMLRPC Server Unspecified Command Execution Vulnerability
BID:14016
Info
Yukihiro Matsumoto Ruby XMLRPC Server Unspecified Command Execution Vulnerability
| Bugtraq ID: | 14016 |
| Class: | Design Error |
| CVE: |
CVE-2005-1992 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2005 12:00AM |
| Updated: | Mar 19 2015 09:27AM |
| Credit: | These issues were reported in Fedora advisories. |
| Vulnerable: |
Yukihiro Matsumoto Ruby 1.8.2 Yukihiro Matsumoto Ruby 1.8 Turbolinux Turbolinux Server 10.0 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Desktop 1.0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Desktop 4.0 Red Hat Enterprise Linux AS 4 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Yukihiro Matsumoto Ruby XMLRPC Server Unspecified Command Execution Vulnerability
Ruby is affected by an unspecified command-execution vulnerability. Reportedly, this issue affects the XMLRPC server.
An attacker may exploit this issue to gain unauthorized access to an affected computer.
Ruby 1.8.2 is known to be vulnerable; other versions may be affected as well.
Ruby is affected by an unspecified command-execution vulnerability. Reportedly, this issue affects the XMLRPC server.
An attacker may exploit this issue to gain unauthorized access to an affected computer.
Ruby 1.8.2 is known to be vulnerable; other versions may be affected as well.
Exploit / POC
Yukihiro Matsumoto Ruby XMLRPC Server Unspecified Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Yukihiro Matsumoto Ruby XMLRPC Server Unspecified Command Execution Vulnerability
Solution:
Please see the referenced advisories for more information.
Yukihiro Matsumoto Ruby 1.8.2
Turbolinux Turbolinux Server 10.0
Solution:
Please see the referenced advisories for more information.
Yukihiro Matsumoto Ruby 1.8.2
-
Debian libdbm-ruby1.8_1.8.2-7sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/r/ruby1.8/libdbm-ruby1.8_ 1.8.2-7sarge1_amd64.deb -
Debian libgdbm-ruby1.8_1.8.2-7sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/r/ruby1.8/libgdbm-ruby1.8 _1.8.2-7sarge1_amd64.deb -
Debian libopenssl-ruby1.8_1.8.2-7sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/r/ruby1.8/libopenssl-ruby 1.8_1.8.2-7sarge1_amd64.deb -
Debian libreadline-ruby1.8_1.8.2-7sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/r/ruby1.8/libreadline-rub y1.8_1.8.2-7sarge1_amd64.deb -
Debian libruby1.8-dbg_1.8.2-7sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8-dbg_ 1.8.2-7sarge1_amd64.deb -
Debian libruby1.8_1.8.2-7sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/r/ruby1.8/libruby1.8_1.8. 2-7sarge1_amd64.deb -
Debian libtcltk-ruby1.8_1.8.2-7sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/r/ruby1.8/libtcltk-ruby1. 8_1.8.2-7sarge1_amd64.deb -
Debian ruby1.8-dev_1.8.2-7sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8-dev_1.8 .2-7sarge1_amd64.deb -
Debian ruby1.8_1.8.2-7sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/r/ruby1.8/ruby1.8_1.8.2-7 sarge1_amd64.deb -
Yukihiro Matsumoto ruby-1.8.2-xmlrpc-ipimethods-fix.diff
http://www.ruby-lang.org/patches/ruby-1.8.2-xmlrpc-ipimethods-fix.diff
Turbolinux Turbolinux Server 10.0
-
TurboLinux ruby-1.8.1-6.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/10/up dates/RPMS/ruby-1.8.1-6.i586.rpm
References
Yukihiro Matsumoto Ruby XMLRPC Server Unspecified Command Execution Vulnerability
References:
References:
- RHSA-2005:543-08 - Moderate: ruby security update (RedHat)
- Ruby Homepage (Yukihiro Matsumoto)
- Ruby XMLRPC.iPIMethods Vulnerability (Yukihiro Matsumoto)