Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900. NOTE: this issue exists because of a regression during Ruby 1.8.6 development.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 2, 2011 |
| Suse | — | Upgrade ruby-develUpgrade rubyUpgrade ruby-examplesUpgrade ruby-tkUpgrade ruby-doc-riUpgrade ruby-test-suiteUpgrade ruby-doc-html | Dec 12, 2013 | Aug 5, 2011 |
| Ubuntu | — | Upgrade libruby1.8Upgrade ruby1.8 | Nov 8, 2024 | Aug 5, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub