CVE-2011-1004

EUVD-2011-1021
The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:N/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
ruby-langruby
1.8.6
ruby-langruby
1.8.7
ruby-langruby
1.8.8:dev
ruby-langruby
1.9.1
ruby-langruby
1.9.2
ruby-langruby
1.9.3:dev
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby1.8
dapper
ignored
hardy
ignored
karmic
ignored
lucid
Fixed 1.8.7.249-2ubuntu0.1
released
maverick
Fixed 1.8.7.299-2ubuntu0.1
released
natty
Fixed 1.8.7.302-2ubuntu0.1
released
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
ruby1.9
dapper
ignored
hardy
ignored
karmic
ignored
lucid
ignored
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
ruby1.9.1
dapper
dne
hardy
dne
karmic
ignored
lucid
ignored
maverick
ignored
natty
ignored
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
References