sqlite3-ruby Package Insecure File Permissions Vulnerability
BID:47694
Info
sqlite3-ruby Package Insecure File Permissions Vulnerability
| Bugtraq ID: | 47694 |
| Class: | Design Error |
| CVE: |
CVE-2011-0995 |
| Remote: | No |
| Local: | Yes |
| Published: | May 03 2011 12:00AM |
| Updated: | May 03 2011 12:00AM |
| Credit: | This issue was disclosed in a SUSE Security Summary Report. |
| Vulnerable: |
SuSE SUSE Linux Enterprise 11 SP1 sqlite3-ruby sqlite3-ruby 0 |
| Not Vulnerable: | |
Discussion
sqlite3-ruby Package Insecure File Permissions Vulnerability
sqlite3-ruby is prone to an insecure-file permissions vulnerability.
An attacker may exploit this vulnerability to overwrite certain files of the package with arbitrary code. The arbitrary code will then run in the context of the programs using the affected package.
sqlite3-ruby is prone to an insecure-file permissions vulnerability.
An attacker may exploit this vulnerability to overwrite certain files of the package with arbitrary code. The arbitrary code will then run in the context of the programs using the affected package.
Exploit / POC
sqlite3-ruby Package Insecure File Permissions Vulnerability
An attacker can use readily available commands to exploit this issue.
An attacker can use readily available commands to exploit this issue.
Solution / Fix
sqlite3-ruby Package Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
sqlite3-ruby Package Insecure File Permissions Vulnerability
References:
References:
- sqlite3-ruby Homepage (sqlite3-ruby)