CVE-2011-3009

Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
ruby-langruby
𝑥
≤ 1.8.6
ruby-langruby
1.8.6:p110
ruby-langruby
1.8.6:p36
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby1.8
hardy
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ruby
RHEL 6
0:1.8.7.352-3.el6
fixed
ruby-devel
RHEL 6
0:1.8.7.352-3.el6
fixed
ruby-docs
RHEL 6
0:1.8.7.352-3.el6
fixed
ruby-irb
RHEL 6
0:1.8.7.352-3.el6
fixed
ruby-libs
RHEL 6
0:1.8.7.352-3.el6
fixed
ruby-rdoc
RHEL 6
0:1.8.7.352-3.el6
fixed
ruby-ri
RHEL 6
0:1.8.7.352-3.el6
fixed
ruby-static
RHEL 6
0:1.8.7.352-3.el6
fixed
ruby-tcltk
RHEL 6
0:1.8.7.352-3.el6
fixed
Common Weakness Enumeration