Ruby 'ARGF.inplace_mode' Buffer Overflow Vulnerability
BID:41321
Info
Ruby 'ARGF.inplace_mode' Buffer Overflow Vulnerability
| Bugtraq ID: | 41321 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-2489 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Masaya TARUI |
| Vulnerable: |
Yukihiro Matsumoto Ruby 1.9.3 dev Yukihiro Matsumoto Ruby 1.9.1 -p376 Yukihiro Matsumoto Ruby 1.9.1 Yukihiro Matsumoto Ruby 1.9 -2 Yukihiro Matsumoto Ruby 1.9 -1 Yukihiro Matsumoto Ruby 1.9 Yukihiro Matsumoto Ruby 1.9.2 pre3 Yukihiro Matsumoto Ruby 1.9.1-p378 Yukihiro Matsumoto Ruby 1.9.0-3 Yukihiro Matsumoto Ruby 1.9 |
| Not Vulnerable: |
Yukihiro Matsumoto Ruby 1.9.2 -rc1 Yukihiro Matsumoto Ruby 1.9.1 -p429 |
Discussion
Ruby 'ARGF.inplace_mode' Buffer Overflow Vulnerability
Ruby is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
This issue is known to be exploitable in Windows environment.
Ruby 1.9.3dev, 1.9.1 patchlevel 378 and prior, and 1.9.2 preview 3 and prior are vulnerable.
Ruby is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
This issue is known to be exploitable in Windows environment.
Ruby 1.9.3dev, 1.9.1 patchlevel 378 and prior, and 1.9.2 preview 3 and prior are vulnerable.
Exploit / POC
Ruby 'ARGF.inplace_mode' Buffer Overflow Vulnerability
An attacker can exploit these issues through readily available tools.
An attacker can exploit these issues through readily available tools.
Solution / Fix
Ruby 'ARGF.inplace_mode' Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ruby 'ARGF.inplace_mode' Buffer Overflow Vulnerability
References:
References:
- Ruby 1.9.1-p429 is released (Yukihiro Matsumoto)
- Ruby 1.9.2 RC1 is released (Yukihiro Matsumoto)
- Ruby Homepage (Yukihiro Matsumoto)