Vulnerability Name:

CVE-2006-3694 (CCN-27725)

Assigned:2006-07-11
Published:2006-07-11
Updated:2017-10-11
Summary:Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations".
CVSS v3 Severity:6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
4.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: SGI
Type: UNKNOWN
20060801-01-P

Source: MITRE
Type: CNA
CVE-2006-3694

Source: JVN
Type: UNKNOWN
JVN#13947696

Source: JVN
Type: UNKNOWN
JVN#83768862

Source: MLIST
Type: UNKNOWN
[freebsd-security] 20060728 Ruby vulnerability?

Source: MLIST
Type: UNKNOWN
[freebsd-security] 20060730 Ruby vulnerability?

Source: CCN
Type: RHSA-2006-0604
ruby security update

Source: CCN
Type: SA21009
Ruby Safe Level Security Bypass Vulnerabilities

Source: SECUNIA
Type: Patch, Vendor Advisory
21009

Source: SECUNIA
Type: Patch, Vendor Advisory
21233

Source: SECUNIA
Type: Patch, Vendor Advisory
21236

Source: SECUNIA
Type: Patch, Vendor Advisory
21272

Source: SECUNIA
Type: Patch, Vendor Advisory
21337

Source: SECUNIA
Type: UNKNOWN
21598

Source: SECUNIA
Type: UNKNOWN
21657

Source: SECUNIA
Type: UNKNOWN
21749

Source: CCN
Type: ASA-2006-150
ruby security update (RHSA-2006-0604)

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-1139

Source: DEBIAN
Type: UNKNOWN
DSA-1157

Source: DEBIAN
Type: DSA-1139
ruby1.6 -- missing privilege checks

Source: DEBIAN
Type: DSA-1157
ruby1.8 -- several vulnerabilities

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2006:134

Source: SUSE
Type: UNKNOWN
SUSE-SR:2006:021

Source: CCN
Type: OpenPKG-SA-2006.016
Ruby

Source: OSVDB
Type: UNKNOWN
27144

Source: OSVDB
Type: UNKNOWN
27145

Source: CCN
Type: OSVDB ID: 27144
Ruby alias Function Safe Level Security Bypass

Source: CCN
Type: OSVDB ID: 27145
Ruby Directory Operations Safe Level Security Bypass

Source: REDHAT
Type: Patch, Vendor Advisory
RHSA-2006:0604

Source: CCN
Type: Ruby Web site
Ruby Home Page

Source: CCN
Type: Ruby CVS Repository
Ruby CVS Repository Guide - Ruby Home Page

Source: BID
Type: Patch
18944

Source: CCN
Type: BID-18944
Yukihiro Matsumoto Ruby Multiple SAFE Level Restriction Bypass Vulnerabilities

Source: CCN
Type: USN-325-1
ruby1.8 vulnerability

Source: UBUNTU
Type: Patch
USN-325-1

Source: VUPEN
Type: UNKNOWN
ADV-2006-2760

Source: XF
Type: UNKNOWN
ruby-alias-directory-security-bypass(27725)

Source: XF
Type: UNKNOWN
ruby-alias-directory-security-bypass(27725)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:9983

Source: SUSE
Type: SUSE-SR:2006:021
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:yukihiro_matsumoto:ruby:1.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:yukihiro_matsumoto:ruby:1.8.3:*:*:*:*:*:*:*
  • OR cpe:/a:yukihiro_matsumoto:ruby:1.8.4:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20063694
    V
    CVE-2006-3694
    2022-05-20
    oval:org.opensuse.security:def:42436
    P
    Security update for expat (Important)
    2022-04-19
    oval:org.opensuse.security:def:31756
    P
    Security update for apache2 (Important)
    2022-01-12
    oval:org.opensuse.security:def:31755
    P
    Security update for libvirt (Important)
    2022-01-10
    oval:org.opensuse.security:def:31373
    P
    Security update for net-snmp (Important)
    2022-01-05
    oval:org.opensuse.security:def:31715
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:26180
    P
    Security update for php74 (Moderate)
    2021-12-06
    oval:org.opensuse.security:def:26179
    P
    Security update for gmp (Moderate)
    2021-12-02
    oval:org.opensuse.security:def:31713
    P
    Security update for clamav (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:31299
    P
    Security update for qemu (Important)
    2021-11-10
    oval:org.opensuse.security:def:32210
    P
    Security update for opensc (Important)
    2021-10-29
    oval:org.opensuse.security:def:26155
    P
    Security update for cairo (Low)
    2021-10-22
    oval:org.opensuse.security:def:32209
    P
    Security update for postgresql10 (Important)
    2021-10-20
    oval:org.opensuse.security:def:31287
    P
    Security update for the Linux Kernel (Live Patch 40 for SLE 12 SP3) (Important)
    2021-10-18
    oval:org.opensuse.security:def:31288
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-10-18
    oval:org.opensuse.security:def:42227
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:26123
    P
    Security update for openssl-1_0_0 (Low)
    2021-09-09
    oval:org.opensuse.security:def:32992
    P
    Security update for gstreamer-plugins-good (Moderate)
    2021-09-02
    oval:org.opensuse.security:def:26115
    P
    Security update for libesmtp (Important)
    2021-09-02
    oval:org.opensuse.security:def:26104
    P
    Security update for libcares2 (Important)
    2021-08-16
    oval:org.opensuse.security:def:32161
    P
    Security update for cpio (Important)
    2021-08-14
    oval:org.opensuse.security:def:26103
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:26102
    P
    Security update for php72 (Important)
    2021-08-06
    oval:org.opensuse.security:def:31654
    P
    Security update for MozillaFirefox (Important)
    2021-07-16
    oval:org.opensuse.security:def:26088
    P
    Security update for the Linux Kernel (Important)
    2021-07-14
    oval:org.opensuse.security:def:32953
    P
    Security update for ovmf (Important)
    2021-06-22
    oval:org.opensuse.security:def:32122
    P
    Security update for apache2 (Important)
    2021-06-17
    oval:org.opensuse.security:def:36289
    P
    ruby-1.8.7.p357-0.9.17.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36554
    P
    ruby-devel-1.8.7.p357-0.9.17.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42696
    P
    ruby-1.8.7.p357-0.9.17.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31191
    P
    Security update for gstreamer-plugins-bad (Important)
    2021-06-07
    oval:org.opensuse.security:def:32105
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:32107
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:26049
    P
    Security update for lz4 (Important)
    2021-05-14
    oval:org.opensuse.security:def:26042
    P
    Security update for cups (Important)
    2021-04-30
    oval:org.opensuse.security:def:32063
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:32065
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:32271
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:26208
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:31741
    P
    Security update for wpa_supplicant (Important)
    2021-03-09
    oval:org.opensuse.security:def:31323
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:32249
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:26146
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:35820
    P
    ruby-1.8.7.p357-0.7.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42044
    P
    ruby-1.8.7.p72-5.24.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36029
    P
    ruby-1.8.7.p357-0.9.9.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:32002
    P
    Security update for gdm (Important)
    2020-12-03
    oval:org.opensuse.security:def:31559
    P
    Security update for gdm (Important)
    2020-12-03
    oval:org.opensuse.security:def:35637
    P
    ruby-1.8.7.p72-5.24.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:31496
    P
    Security update for python-imaging
    2020-12-01
    oval:org.opensuse.security:def:32365
    P
    Security update for supportutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31881
    P
    Security update for dnsmasq (Important)
    2020-12-01
    oval:org.opensuse.security:def:25189
    P
    Security update for ucode-intel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25947
    P
    Security update for freerdp (Important)
    2020-12-01
    oval:org.opensuse.security:def:32041
    P
    Security update for krb5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27287
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25578
    P
    Security update for python-ipaddress (Important)
    2020-12-01
    oval:org.opensuse.security:def:31581
    P
    Security update for tar (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26264
    P
    Security update for gegl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32470
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:32563
    P
    libpulse-browse0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25264
    P
    Security update for memcached (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31472
    P
    Security update for ppp (Important)
    2020-12-01
    oval:org.opensuse.security:def:32315
    P
    Security update for rsync (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25590
    P
    Security update for dovecot22 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31805
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26468
    P
    Security update for go1.9 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25964
    P
    Security update for libraw (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25473
    P
    Security update for strongswan (Important)
    2020-12-01
    oval:org.opensuse.security:def:26310
    P
    Security update for Cloud Compute 12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25782
    P
    Security update for evolution-data-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31949
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26556
    P
    gmime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26637
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25614
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:31820
    P
    Security update for augeas (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26992
    P
    mozilla-xulrunner192 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25920
    P
    Security update for gstreamer-plugins-base (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26879
    P
    cvs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26388
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25818
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:25371
    P
    Security update for python-ipaddress (Important)
    2020-12-01
    oval:org.opensuse.security:def:31505
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27552
    P
    ruby-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25838
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31841
    P
    Security update for bzip2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26529
    P
    cifs-mount on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25906
    P
    Security update for sane-backends (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32745
    P
    lvm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25446
    P
    Security update for nfs-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26257
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32575
    P
    log4net on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25850
    P
    Security update for libreoffice (Low)
    2020-12-01
    oval:org.opensuse.security:def:26733
    P
    lcms on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31106
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25655
    P
    Security update for spice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31897
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:26570
    P
    kdebase3-runtime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33252
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31495
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:26821
    P
    squid3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26819
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25188
    P
    Security update for texlive (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25796
    P
    Security update for util-linux (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27252
    P
    openslp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31507
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32421
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31925
    P
    Security update for ghostscript-library (Important)
    2020-12-01
    oval:org.opensuse.security:def:25200
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:31415
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26000
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25579
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:26415
    P
    Security update for python-Django (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32509
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32602
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25392
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:25654
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:31862
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26517
    P
    NetworkManager-gnome on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26602
    P
    libsndfile on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25530
    P
    Security update for virglrenderer (Important)
    2020-12-01
    oval:org.opensuse.security:def:31771
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLED, firefox-gcc5, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:26354
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25863
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26835
    P
    unrar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26307
    P
    Security update for conntrack-tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25765
    P
    Security update for Adobe Flash Player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31859
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27027
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25370
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:26004
    P
    Security update for shotwell (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27517
    P
    mozilla-nss-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31767
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26445
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25867
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25382
    P
    Security update for squid (Critical)
    2020-12-01
    oval:org.opensuse.security:def:31597
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32531
    P
    ipsec-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25839
    P
    Security update for gimp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31973
    P
    Security update for jakarta-taglibs-standard (Important)
    2020-12-01
    oval:org.opensuse.security:def:26680
    P
    cups on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32784
    P
    ruby on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31105
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:25574
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26296
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33213
    P
    nfs-client on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25914
    P
    Security update for firebird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26782
    P
    man on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26784
    P
    mono-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31117
    P
    Security update for krb5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25712
    P
    Security update for python36 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31953
    P
    Security update for gstreamer-0_10-plugins-base (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26614
    P
    mozilla-xulrunner190 on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:9983
    V
    Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations".
    2013-04-29
    oval:org.debian:def:1157
    V
    several vulnerabilities
    2006-08-27
    oval:org.debian:def:1139
    V
    missing privilege checks
    2006-08-03
    oval:com.redhat.rhsa:def:20060604
    P
    RHSA-2006:0604: ruby security update (Moderate)
    2006-07-27
    BACK
    yukihiro_matsumoto ruby 1.8.2
    yukihiro_matsumoto ruby 1.8.3
    yukihiro_matsumoto ruby 1.8.4