Oval Definition:oval:org.opensuse.security:def:20124481
Revision Date:2022-05-20Version:1
Title:CVE-2012-4481
Description:

The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2012-4481
Mitre CVE-2012-4481
SUSE CVE-2012-4481
SUSE-SU-2014:0844-1
SUSE-SU-2014:0844-1
Platform(s):SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Server 11 SP1 LTSS
SUSE Linux Enterprise Server 11 SP1-LTSS
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP2 for VMware
SUSE Linux Enterprise Server for SAP Applications 11 SP1-LTSS
SUSE Linux Enterprise Software Development Kit 11 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 11 SP1-LTSS is installed
  • AND Package Information
  • ruby-1.8.7.p357-0.9.15.6 is installed
  • OR ruby-doc-html-1.8.7.p357-0.9.15.6 is installed
  • OR ruby-tk-1.8.7.p357-0.9.15.6 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP1-LTSS is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 SP1-LTSS is installed
  • AND Package Information
  • ruby-1.8.7.p357-0.9.15 is installed
  • OR ruby-doc-html-1.8.7.p357-0.9.15 is installed
  • OR ruby-tk-1.8.7.p357-0.9.15 is installed
  • BACK