CVE-2009-4124
https://notcve.org/view.php?id=CVE-2009-4124
Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving (1) String#ljust, (2) String#center, or (3) String#rjust. NOTE: some of these details are obtained from third party information. Desbordamiento del búfer de la memoria dinámica en la función rb_str_justify en string.c en Ruby v1.9.1 en versiones anteriores a v1.9.1-p376 atacantes dependientes del contexto podrían ejecutar código arbitrario a través de vectores sin especificar que incluyen (1) String#ljust, (2) String#center, o (3) String#rjust. NOTA: Algunos de los detalles han sido obtenidos de terceros. • http://secunia.com/advisories/37660 http://www.osvdb.org/60880 http://www.ruby-lang.org/en/news/2009/12/07/heap-overflow-in-string http://www.securityfocus.com/bid/37278 http://www.vupen.com/english/advisories/2009/3471 https://exchange.xforce.ibmcloud.com/vulnerabilities/54674 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2009-1904 – ruby: DoS vulnerability in BigDecimal
https://notcve.org/view.php?id=CVE-2009-1904
The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type. La librería BigDecimal en Ruby v1.8.6 anteriores p369 y v1.8.7, anteriores a p173 permite a los atacantes dependientes del contexto causar una denegación de servicio (caída de la aplicación) a través de un argumento de cadena de caracteres que representa un número largo, como se demuestra por un intento de conversión al tipo de dato Float. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=532689 http://bugs.gentoo.org/show_bug.cgi?id=273213 http://github.com/NZKoz/bigdecimal-segfault-fix/tree/master http://groups.google.com/group/rubyonrails-security/msg/fad60751e2b9b4f6?dmode=source http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html http://mail-index.netbsd.org/pkgsrc-changes/2009/06/10/msg024708.html http://osvdb.org/55031 http://redmine.ruby-lang.org/issues/show/794 http://secunia.c • CWE-189: Numeric Errors •
CVE-2009-0642 – ruby: Incorrect checks for validity of X.509 certificates
https://notcve.org/view.php?id=CVE-2009-0642
ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate. ext/openssl/ossl_ocsp.c en Ruby v1.8 y v1.9 no comprueba adecuadamente el valor de retorno de la funcion OCSP_basic_verify, lo cual permitiria a atacantes remotos tener exito en la presentacion de un certificado X.509 invalido, posiblemente utilizando un certificado revocado. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=513528 http://redmine.ruby-lang.org/issues/show/1091 http://secunia.com/advisories/33750 http://secunia.com/advisories/35699 http://secunia.com/advisories/35937 http://www.mandriva.com/security/advisories?name=MDVSA-2009:193 http://www.redhat.com/support/errata/RHSA-2009-1140.html http://www.securityfocus.com/bid/33769 http://www.securitytracker.com/id?1022505 http://www.ubuntu.com/usn/USN-805-1 https://exchange.xfor • CWE-287: Improper Authentication •
CVE-2008-4310 – Ruby 1.9 - 'WEBrick::HTTP::DefaultFileHandler' Crafted HTTP Request Denial of Service
https://notcve.org/view.php?id=CVE-2008-4310
httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request. NOTE: this issue exists because of an incomplete fix for CVE-2008-3656. El archivo httputils.rb en WEBrick en Ruby versiones 1.8.1 y 1.8.5, tal y como es usado en versiones 4 y 5 de Red Hat Enterprise Linux, permite a los atacantes remotos causar una denegación de servicio (consumo de CPU) por medio de una petición HTTP diseñada. NOTA: este problema se presenta debido a una corrección incompleta del CVE-2008-3656. • https://www.exploit-db.com/exploits/32222 http://secunia.com/advisories/33013 http://www.openwall.com/lists/oss-security/2008/12/04/2 http://www.redhat.com/support/errata/RHSA-2008-0981.html https://bugzilla.redhat.com/show_bug.cgi?id=470252 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10250 https://access.redhat.com/security/cve/CVE-2008-4310 • CWE-399: Resource Management Errors •
CVE-2008-3905 – ruby: use of predictable source port and transaction id in DNS requests done by resolv.rb module
https://notcve.org/view.php?id=CVE-2008-3905
resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. resolv.rb en Ruby 1.8.5 y versiones anteriores, 1.8.6 versiones anteriores a 1.8.6-p287, 1.8.7 versiones anteriores a 1.8.7-p72, y 1.9 r18423 y versiones anteriores utiliza transacciones secuenciales de IDs y puertos de origen constante para peticiones DNS, lo cual hace más sencillo para atacantes remotos envenenar respuestas DNS, una vulnerabilidad diferente a CVE-2008-1447. • http://secunia.com/advisories/31430 http://secunia.com/advisories/32165 http://secunia.com/advisories/32219 http://secunia.com/advisories/32255 http://secunia.com/advisories/32256 http://secunia.com/advisories/32371 http://secunia.com/advisories/32948 http://secunia.com/advisories/33178 http://security.gentoo.org/glsa/glsa-200812-17.xml http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.371754 http://support.avaya.com/elmodocs2/security/ASA- • CWE-287: Improper Authentication •