JRuby Insecure Library Loading Arbitrary Code Execution Vulnerability
BID:60918
Info
JRuby Insecure Library Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 60918 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2010 12:00AM |
| Updated: | Dec 22 2010 12:00AM |
| Credit: | Charles Oliver Nutter |
| Vulnerable: |
JRuby JRuby 1.6 |
| Not Vulnerable: |
JRuby JRuby 1.6.4 |
Discussion
JRuby Insecure Library Loading Arbitrary Code Execution Vulnerability
JRuby is prone to a vulnerability that lets attackers execute arbitrary code.
Attacker can leverage this issue to execute arbitrary code in the context of the user running the affected application.
JRuby 1.6 is vulnerable; other versions may also be affected.
JRuby is prone to a vulnerability that lets attackers execute arbitrary code.
Attacker can leverage this issue to execute arbitrary code in the context of the user running the affected application.
JRuby 1.6 is vulnerable; other versions may also be affected.
Exploit / POC
JRuby Insecure Library Loading Arbitrary Code Execution Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
JRuby Insecure Library Loading Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
JRuby Insecure Library Loading Arbitrary Code Execution Vulnerability
References:
References: