Vulnerability Database

289,689

Total vulnerabilities in the database

CVE-2012-4466

Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the name_err_mesg_to_str API function, which marks the string as tainted, a different vulnerability than CVE-2011-1005.

  • Published: Apr 26, 2013
  • Updated: Apr 13, 2023
  • CVE: CVE-2012-4466
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:P/A:N

CWEs:

Software From Fixed in
ruby-lang / ruby 1.8.7-p370 1.8.7-p370.x
ruby-lang / ruby 1.8.7-p330 1.8.7-p330.x
ruby-lang / ruby 1.8.7-p334 1.8.7-p334.x
ruby-lang / ruby 1.8.7-p248 1.8.7-p248.x
ruby-lang / ruby 2.0.0 2.0.0.x
ruby-lang / ruby 1.8.7-preview3 1.8.7-preview3.x
ruby-lang / ruby 1.8.7-p17 1.8.7-p17.x
ruby-lang / ruby 1.8.7-p299 1.8.7-p299.x
ruby-lang / ruby 2.0 2.0.x
ruby-lang / ruby 1.8.7-p357 1.8.7-p357.x
ruby-lang / ruby 1.8.7-p71 1.8.7-p71.x
ruby-lang / ruby 1.8.7-p22 1.8.7-p22.x
ruby-lang / ruby 2.0.0-preview1 2.0.0-preview1.x
ruby-lang / ruby 1.8.7-p352 1.8.7-p352.x
ruby-lang / ruby 1.8.7-p301 1.8.7-p301.x
ruby-lang / ruby 1.8.7-p358 1.8.7-p358.x
ruby-lang / ruby 1.8.7-p160 1.8.7-p160.x
ruby-lang / ruby 1.8.7-preview2 1.8.7-preview2.x
ruby-lang / ruby 1.8.7-p174 1.8.7-p174.x
ruby-lang / ruby 2.0.0-p0 2.0.0-p0.x
ruby-lang / ruby 1.9.3-p125 1.9.3-p125.x
ruby-lang / ruby 2.0.0-rc1 2.0.0-rc1.x
ruby-lang / ruby 2.0.0-preview2 2.0.0-preview2.x
ruby-lang / ruby 1.9.3-p194 1.9.3-p194.x
ruby-lang / ruby 1.8.7 1.8.7.x
ruby-lang / ruby 1.8.7-p173 1.8.7-p173.x
ruby-lang / ruby 1.8.7-p249 1.8.7-p249.x
ruby-lang / ruby 1.9.3 1.9.3.x
ruby-lang / ruby 2.0.0-rc2 2.0.0-rc2.x
ruby-lang / ruby 1.8.7-preview1 1.8.7-preview1.x
ruby-lang / ruby 1.8.7-p302 1.8.7-p302.x
ruby-lang / ruby 1.8.7-p72 1.8.7-p72.x
ruby-lang / ruby 1.9.3-p0 1.9.3-p0.x
ruby-lang / ruby 1.8.7-preview4 1.8.7-preview4.x