[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2021-1505 --- ruby20 packages

ID: oval:org.secpod.oval:def:1601441Date: (C)2021-05-31   (M)2024-01-29
Class: PATCHFamily: unix




RDoc before version 6.3.1 used to call Kernel#open to open a local file. If a Ruby project has a file whose name starts with "|" and ends with "tags", the command following the pipe character is executed. A malicious Ruby project could exploit it to run an arbitrary command execution against a user who attempts to run the rdoc command

Platform:
Amazon Linux AMI
Product:
ruby20
rubygem20
rubygems20
Reference:
ALAS-2021-1505
CVE-2021-31799
CVE    1
CVE-2021-31799
CPE    4
cpe:/o:amazon:linux
cpe:/a:ruby:rubygems20
cpe:/a:ruby:ruby20
cpe:/a:ruby:rubygem20
...

© SecPod Technologies