← Back

CVE-2010-2489

nvd nist
Published: Jul 12, 2010Modified: Apr 29, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properly handled when constructing the filenames of the backup files.

Affected (14)

Products: Ruby Lang: Ruby
1 product
Ruby
Configuration A
14 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Ruby Lang
Version 1.9.0-0
Version 1.9.0-1
Version 1.9.0-20060415
Version 1.9.0-20070709
Version 1.9.0-2
Version 1.9.1 -p0
Version 1.9.1 -p129
Version 1.9.1 -p243
Version 1.9.1 -p376
Version 1.9.1 -p429
Version 1.9.1 -preview_1
Version 1.9.1 -preview_2
Version 1.9.1 -rc1
Version 1.9.1 -rc2
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (20)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.