CVE-2011-1004
Published Mar 2, 2011
Last updated 13 years ago
Overview
- Description
- The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.3
- Impact score
- 9.2
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:N/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-59
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ruby-lang:ruby:1.8.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "876B2575-4F81-4A70-9A88-9BEE44649626" }, { "criteria": "cpe:2.3:a:ruby-lang:ruby:1.8.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D86FC99-3521-4E22-8FD3-65CEB05A6342" }, { "criteria": "cpe:2.3:a:ruby-lang:ruby:1.8.8:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FAFAB6A-3299-4BEE-BDB9-3918DDA5D3DB" }, { "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C78BB1D8-0505-484D-B824-1AA219F8B247" }, { "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5178D04D-1C29-4353-8987-559AA07443EC" }, { "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.3:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02941FD6-BF48-4435-AAB0-BC26C1805293" } ], "operator": "OR" } ] } ]