[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2021-1506 --- ruby24 packages

ID: oval:org.secpod.oval:def:1601442Date: (C)2021-05-31   (M)2024-01-29
Class: PATCHFamily: unix




RDoc before version 6.3.1 used to call Kernel#open to open a local file. If a Ruby project has a file whose name starts with "|" and ends with "tags", the command following the pipe character is executed. A malicious Ruby project could exploit it to run an arbitrary command execution against a user who attempts to run the rdoc command

Platform:
Amazon Linux AMI
Product:
ruby24
rubygem24
rubygems24
Reference:
ALAS-2021-1506
CVE-2021-31799
CVE    1
CVE-2021-31799
CPE    4
cpe:/o:amazon:linux
cpe:/a:ruby:ruby24
cpe:/a:ruby:rubygems24
cpe:/a:ruby:rubygem24
...

© SecPod Technologies