Vulnerability Name:
CVE-2010-2489 (CCN-60135)
Assigned:
2010-07-04
Published:
2010-07-04
Updated:
2017-08-17
Summary:
Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properly handled when constructing the filenames of the backup files.
CVSS v3 Severity:
5.9 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
Low
Availibility (A):
Low
CVSS v2 Severity:
7.2 High
(CVSS v2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
)
5.3 Medium
(Temporal CVSS v2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
4.6 Medium
(CCN CVSS v2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P
)
3.4 Low
(CCN Temporal CVSS v2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
Vulnerability Type:
CWE-119
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2010-2489
Source: MLIST
Type: UNKNOWN
[ruby-talk] 20100702 Re: [ANN][Security] Ruby 1.9.1-p429 is out
Source: CCN
Type: SA40442
Ruby ARGF.inplace_mode Buffer Overflow Vulnerability
Source: SECUNIA
Type: Vendor Advisory
40442
Source: CONFIRM
Type: UNKNOWN
http://svn.ruby-lang.org/repos/ruby/tags/v1_9_1_429/ChangeLog
Source: CONFIRM
Type: UNKNOWN
http://svn.ruby-lang.org/repos/ruby/tags/v1_9_2_rc1/ChangeLog
Source: MLIST
Type: UNKNOWN
[oss-security] 20100702 CVE Request [Microsoft Windows Ruby-v1.9.x] -- Buffer over-run leading to ACE
Source: MLIST
Type: UNKNOWN
[oss-security] 20100702 Re: CVE Request [Microsoft Windows Ruby-v1.9.x] -- Buffer over-run leading to ACE
Source: OSVDB
Type: UNKNOWN
66040
Source: CCN
Type: OSVDB ID: 66040
Ruby on Windows ARGF.inplace_mode Variable Local Overflow
Source: CCN
Type: Ruby Web site
Ruby 1.9.1-p429 is released
Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.ruby-lang.org/en/news/2010/07/02/ruby-1-9-1-p429-is-released/
Source: BID
Type: UNKNOWN
41321
Source: CCN
Type: BID-41321
Ruby 'ARGF.inplace_mode' Buffer Overflow Vulnerability
Source: XF
Type: UNKNOWN
ruby-argfinplacemode-bo(60135)
Source: XF
Type: UNKNOWN
ruby-argfinplacemode-bo(60135)
Vulnerable Configuration:
Configuration 1
:
cpe:/a:ruby-lang:ruby:1.9.0-0:*:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.0-1:*:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.0-2:*:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.0-20060415:*:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.0-20070709:*:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:-p0:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:-p129:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:-p243:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:-p376:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:-p429:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:-preview_1:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:-preview_2:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:-rc1:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:-rc2:*:*:*:*:*:*
AND
cpe:/o:microsoft:windows:*:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:ruby-lang:ruby:1.9:*:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:*:*:*:*:*:*:*
OR
cpe:/a:ruby-lang:ruby:1.9.1:-p129:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
ruby-lang
ruby 1.9.0-0
ruby-lang
ruby 1.9.0-1
ruby-lang
ruby 1.9.0-2
ruby-lang
ruby 1.9.0-20060415
ruby-lang
ruby 1.9.0-20070709
ruby-lang
ruby 1.9.1 -p0
ruby-lang
ruby 1.9.1 -p129
ruby-lang
ruby 1.9.1 -p243
ruby-lang
ruby 1.9.1 -p376
ruby-lang
ruby 1.9.1 -p429
ruby-lang
ruby 1.9.1 -preview_1
ruby-lang
ruby 1.9.1 -preview_2
ruby-lang
ruby 1.9.1 -rc1
ruby-lang
ruby 1.9.1 -rc2
microsoft
windows *
ruby-lang
ruby 1.9
ruby-lang
ruby 1.9.1
ruby-lang
ruby 1.9.1 -p129