Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin).
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Ruby | — | Apply OS X security update 2006-003 | Dec 16, 2011 | Oct 7, 2005 |
| Freebsd | — | Upgrade rubyUpgrade ruby_static | Dec 10, 2025 | Oct 27, 2005 |
| Gentoo Linux | — | Upgrade dev-lang/ruby. | Oct 30, 2017 | Oct 7, 2005 |
| Suse | — | Upgrade ruby | Feb 17, 2015 | Oct 7, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub