Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Gentoo: GLSA 200507-10 High: Ruby Remote Command Execution

gentoo
Calendar Grey July 11, 2005
Scroller Gentoo
Gentoo advisory GLSA 202310-15: Critical vulnerability in Python enables remote code execution through JSON-RPC interface.
A vulnerability in XMLRPC.iPIMethods allows remote attackers to execute arbitrary commands.

Summary

Gentoo Linux Security Advisory GLSA 200507-10 https://security.gentoo.org/ Severity: High Title: Ruby: Arbitrary command execution through XML-RPC Date: July 11, 2005 Bugs: #96784 ID: 200507-10

Synopsis ======= A vulnerability in XMLRPC.iPIMethods allows remote attackers to execute arbitrary commands.
Background ========= Ruby is an interpreted scripting language for quick and easy object-oriented programming. XML-RPC is a remote procedure call protocol encoded in XML.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-lang/ruby < 1.8.2-r2 >= 1.8.2-r2
========== Nobuhiro IMAI reported that an invalid default value in "utils.rb" causes the security p...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround