Red Hat Bugzilla – Bug 458966
CVE-2008-3657 ruby: missing "taintness" checks in dl module
Last modified: 2011-10-27 09:12:29 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-3657 to the following vulnerability:
The dl module in Ruby 1.8.5 and earlier, 1.8.5 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.
Created attachment 314211 [details]
Please notice, the previous proposed patch for the Ruby dl module was
incomplete. See part:
Ruby 1.8.7-p72 and 1.8.6-p287 released
Ruby 1.8.7-p72 and 1.8.6-p287 have been released. The last releases were incomplete, and the new releases include fixes of the previously announced vulnerability of dl.
ruby-22.214.171.1247-2.fc8 has been submitted as an update for Fedora 8.
ruby-126.96.36.1997-2.fc9 has been submitted as an update for Fedora 9.
ruby-188.8.131.527-2.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
ruby-184.108.40.2067-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
This issue was addressed in:
Red Hat Enterprise Linux: