rubysec / ruby-advisory-db

A database of vulnerable Ruby Gems
https://rubysec.com
Other
1.02k stars 219 forks source link

Add advisory for ruby DL::Function#call issue, fixed in ruby-1.9.1-p129 #228

Closed reedloden closed 1 year ago

reedloden commented 8 years ago

This was never assigned a CVE / OSVDB identifier (requested here), so it's not tracked at all:

I requested one from MITRE, but they had some questions, which security@ruby-lang.org has yet to respond to: http://seclists.org/oss-sec/2015/q3/222. I just sent them another poke.

@JuanitoFatas, perhaps you can poke somebody to reply to my e-mail? ;)

reedloden commented 8 years ago

@unak just replied to my poke, but still lacking the correct info, I think.

jasnow commented 1 year ago

Found these possible references:

postmodern commented 1 year ago

Confirmed CVE-2013-2065 is discussing the DL::Function#call tainting issue.