Sha256: 1a4349514909aeedb4822eb1af69d80613b359cf65a40d265ae6489057e71310

Contents?: true

Size: 430 Bytes

Versions: 6

Compression:

Stored size: 430 Bytes

Contents

--- 
gem: fileutils
osvdb: 90716
url: http://osvdb.org/show/osvdb/90716
title: fileutils Gem for Ruby Temporary Directory Hijacking Weakness
date: 2013-02-28
description: fileutils Gem for Ruby contains a flaw that is due to the program not verifying the existence of a directory before attempting to create it. This may allow a local attacker to create the directory in advance, thus owning any files subsequently written to it.

Version data entries

6 entries across 6 versions & 2 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/fileutils/OSVDB-90716.yml
bundler-budit-0.6.2 data/ruby-advisory-db/gems/fileutils/OSVDB-90716.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/fileutils/OSVDB-90716.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/fileutils/OSVDB-90716.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/fileutils/OSVDB-90716.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/fileutils/OSVDB-90716.yml