Vulnerability Description
Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) "..%5c" (encoded backslash) sequences or (2) filenames that match patterns in the :NondisclosureName option.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ruby-Lang | Webrick | - |
| Ruby-Lang | Ruby | >= 1.8.0, < 1.8.5.115 |
| Fedoraproject | Fedora | 7 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlBroken LinkMailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlMailing ListThird Party Advisory
- http://secunia.com/advisories/29232Not ApplicableVendor Advisory
- http://secunia.com/advisories/29357Not ApplicableVendor Advisory
- http://secunia.com/advisories/29536Not Applicable
- http://secunia.com/advisories/30802Not Applicable
- http://secunia.com/advisories/31687Not Applicable
- http://secunia.com/advisories/32371Not Applicable
- http://support.apple.com/kb/HT2163Third Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2008-0123Broken Link
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0123Broken Link
- http://www.kb.cert.org/vuls/id/404515Third Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:141Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:142Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0897.htmlThird Party Advisory
FAQ
What is CVE-2008-1145?
CVE-2008-1145 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensiti...
How severe is CVE-2008-1145?
CVE-2008-1145 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1145?
Check the references section above for vendor advisories and patch information. Affected products include: Ruby-Lang Webrick, Ruby-Lang Ruby, Fedoraproject Fedora.