Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properly handled when constructing the filenames of the backup files.
2010-07-12T13:27:27.813
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ruby-lang | ruby | 1.9.0-0 | Yes |
Application | ruby-lang | ruby | 1.9.0-1 | Yes |
Application | ruby-lang | ruby | 1.9.0-2 | Yes |
Application | ruby-lang | ruby | 1.9.0-20060415 | Yes |
Application | ruby-lang | ruby | 1.9.0-20070709 | Yes |
Application | ruby-lang | ruby | 1.9.1 | Yes |
Application | ruby-lang | ruby | 1.9.1 | Yes |
Application | ruby-lang | ruby | 1.9.1 | Yes |
Application | ruby-lang | ruby | 1.9.1 | Yes |
Application | ruby-lang | ruby | 1.9.1 | Yes |
Application | ruby-lang | ruby | 1.9.1 | Yes |
Application | ruby-lang | ruby | 1.9.1 | Yes |
Application | ruby-lang | ruby | 1.9.1 | Yes |
Application | ruby-lang | ruby | 1.9.1 | Yes |
Operating System | microsoft | windows | * | No |