Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the name_err_mesg_to_str API function, which marks the string as tainted, a different vulnerability than CVE-2011-1005.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade ruby | Dec 10, 2025 | Nov 1, 2012 |
| Suse | — | Upgrade ruby-doc-riUpgrade ruby-tkUpgrade ruby-test-suiteUpgrade ruby-doc-htmlUpgrade ruby-examplesUpgrade rubyUpgrade ruby-devel | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libruby1.8Upgrade libruby1.9.1 | Nov 8, 2024 | Apr 25, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub