Ruby CVE-2012-4522 Local File Creation Vulnerability
BID:56115
Info
Ruby CVE-2012-4522 Local File Creation Vulnerability
| Bugtraq ID: | 56115 |
| Class: | Design Error |
| CVE: |
CVE-2012-4522 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 18 2012 12:00AM |
| Updated: | May 07 2015 05:05PM |
| Credit: | Peter Bex |
| Vulnerable: |
Yukihiro Matsumoto Ruby 1.9.3 dev Yukihiro Matsumoto Ruby 1.9.2 RC2 Yukihiro Matsumoto Ruby 1.9.2 P180 Yukihiro Matsumoto Ruby 1.9.2 P136 Yukihiro Matsumoto Ruby 1.9.2 P0 Yukihiro Matsumoto Ruby 1.9.2 -rc1 Yukihiro Matsumoto Ruby 1.9.1 P431 Yukihiro Matsumoto Ruby 1.9.1 -p429 Yukihiro Matsumoto Ruby 1.9.1 -p376 Yukihiro Matsumoto Ruby 1.9.1 Yukihiro Matsumoto Ruby 1.9 -2 Yukihiro Matsumoto Ruby 1.9 -1 Yukihiro Matsumoto Ruby 1.9 Yukihiro Matsumoto Ruby 1.9.3-p0 Yukihiro Matsumoto Ruby 1.9.2 pre3 Yukihiro Matsumoto Ruby 1.9.1-p430 Yukihiro Matsumoto Ruby 1.9.1-p378 Yukihiro Matsumoto Ruby 1.9.0-3 Yukihiro Matsumoto Ruby 1.9 Ubuntu Ubuntu Linux 12.10 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 S.u.S.E. openSUSE 12.2 Redhat OpenShift Enterprise 0 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Enterprise Linux 5 CentOS CentOS 5 |
| Not Vulnerable: | |
Discussion
Ruby CVE-2012-4522 Local File Creation Vulnerability
Ruby is prone to a security vulnerability that may allow attackers to create unintended files.
Successfully exploiting this issue will allow attackers to create unintended files. This may allow attackers to cause a denial-of-service condition or execute arbitrary code.
Ruby is prone to a security vulnerability that may allow attackers to create unintended files.
Successfully exploiting this issue will allow attackers to create unintended files. This may allow attackers to cause a denial-of-service condition or execute arbitrary code.
Exploit / POC
Ruby CVE-2012-4522 Local File Creation Vulnerability
An attacker can exploit this issue by using readily available command line utilities.
An attacker can exploit this issue by using readily available command line utilities.