Your submission was sent successfully! Close

CVE-2011-1004

Published: 2 March 2011

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.

Priority

Low

Status

Package Release Status
ruby1.8
Launchpad, Ubuntu, Debian
dapper Ignored
(reached end-of-life)
hardy Ignored
(reached end-of-life)
karmic Ignored
(reached end-of-life)
lucid
Released (1.8.7.249-2ubuntu0.1)
maverick
Released (1.8.7.299-2ubuntu0.1)
natty
Released (1.8.7.302-2ubuntu0.1)
oneiric Not vulnerable
(1.8.7.352-2)
precise Not vulnerable
(1.8.7.352-2)
quantal Not vulnerable
(1.8.7.352-2)
raring Not vulnerable
(1.8.7.352-2)
saucy Not vulnerable
(1.8.7.352-2)
upstream
Released (1.8.7.334-1)
Patches:
other: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&revision=30896
ruby1.9
Launchpad, Ubuntu, Debian
dapper Ignored
(reached end-of-life)
hardy Ignored
(reached end-of-life)
karmic Ignored
(reached end-of-life)
lucid Ignored
(reached end-of-life)
maverick Does not exist

natty Does not exist

oneiric Does not exist

precise Does not exist

quantal Does not exist

raring Does not exist

saucy Does not exist

upstream Needs triage

ruby1.9.1
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

karmic Ignored
(reached end-of-life)
lucid Ignored
(reached end-of-life)
maverick Ignored
(reached end-of-life)
natty Ignored
(reached end-of-life)
oneiric Not vulnerable
(1.9.2.290-2)
precise Not vulnerable

quantal Not vulnerable

raring Not vulnerable

saucy Not vulnerable

upstream
Released (1.9.2.180-1)