(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native functions, which allows context-dependent attackers to bypass intended $SAFE level restrictions.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade ruby19 | Dec 10, 2025 | May 26, 2013 |
| Suse | — | Upgrade ruby19-devel-extraUpgrade ruby19-tkUpgrade ruby19-doc-riUpgrade ruby19Upgrade ruby19-devel | Dec 12, 2013 | Nov 2, 2013 |
| Ubuntu | — | Upgrade libruby1.9.1Upgrade ruby1.9.1Upgrade ruby1.8Upgrade libruby1.8 | Nov 8, 2024 | Nov 2, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub