Back

MEDIUM

ruby: Incomplete fix for CVE-2011-1005 for NameError#to_s method when used on objects

Published May 2, 2013

Description

The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 2, 2013
Updated Aug 6, 2024
Reserved Aug 21, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Oct 5, 2012