Back to search
CVE-2012-4522
Published: Nov 24, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2012-16071
vendor-advisory
x_refsource_FEDORA
FEDORA-2012-16086
vendor-advisory
x_refsource_FEDORA
[oss-security] 20121013 Re: CVE request: ruby file creation due in insertion of illegal NUL character
mailing-list
x_refsource_MLIST
RHSA-2013:0129
vendor-advisory
x_refsource_REDHAT
[oss-security] 20121016 Re: CVE request: ruby file creation due in insertion of illegal NUL character
mailing-list
x_refsource_MLIST
[oss-security] 20121012 CVE request: ruby file creation due in insertion of illegal NUL character
mailing-list
x_refsource_MLIST
http://www.ruby-lang.org/en/news/2012/10/12/poisoned-NUL-byte-vulnerability/
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now