Sha256: 84c6498e0097746ae89b7ee6dd4b450bf01da4e16da134f5b09d71315e2f3169

Contents?: true

Size: 495 Bytes

Versions: 6

Compression:

Stored size: 495 Bytes

Contents

---
gem: builder
osvdb: 95668
url: http://osvdb.org/show/osvdb/95668
title: Builder Gem for Ruby Tag Name Handling Private Method Exposure
date: 2007-06-15
description: |
  Builder Gem for Ruby contains a flaw in the handling of tag names. The issue
  is triggered when the program reads tag names from XML data and then calls a
  method with that name. With a specially crafted file, a context-dependent
  attacker can call private methods and manipulate data.
patched_versions:
  - ">= 2.1.2"

Version data entries

6 entries across 6 versions & 2 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/builder/OSVDB-95668.yml
bundler-budit-0.6.2 data/ruby-advisory-db/gems/builder/OSVDB-95668.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/builder/OSVDB-95668.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/builder/OSVDB-95668.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/builder/OSVDB-95668.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/builder/OSVDB-95668.yml