CVE-2011-1004

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:N/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
ruby-langruby
1.8.6
ruby-langruby
1.8.7
ruby-langruby
1.8.8:dev
ruby-langruby
1.9.1
ruby-langruby
1.9.2
ruby-langruby
1.9.3:dev
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby1.8
dapper
ignored
hardy
ignored
karmic
ignored
lucid
Fixed 1.8.7.249-2ubuntu0.1
released
maverick
Fixed 1.8.7.299-2ubuntu0.1
released
natty
Fixed 1.8.7.302-2ubuntu0.1
released
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
ruby1.9
dapper
ignored
hardy
ignored
karmic
ignored
lucid
ignored
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
ruby1.9.1
dapper
dne
hardy
dne
karmic
ignored
lucid
ignored
maverick
ignored
natty
ignored
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ruby
RHEL 6
0:1.8.7.299-7.el6_1.1
fixed
ruby-devel
RHEL 6
0:1.8.7.299-7.el6_1.1
fixed
ruby-docs
RHEL 6
0:1.8.7.299-7.el6_1.1
fixed
ruby-irb
RHEL 6
0:1.8.7.299-7.el6_1.1
fixed
ruby-libs
RHEL 6
0:1.8.7.299-7.el6_1.1
fixed
ruby-rdoc
RHEL 6
0:1.8.7.299-7.el6_1.1
fixed
ruby-ri
RHEL 6
0:1.8.7.299-7.el6_1.1
fixed
ruby-static
RHEL 6
0:1.8.7.299-7.el6_1.1
fixed
ruby-tcltk
RHEL 6
0:1.8.7.299-7.el6_1.1
fixed
References