MEDIUM · 6.3

CVE-2011-1004

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete...

Vulnerability Description

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.

CVSS Score

6.3

MEDIUM

AV:L/AC:M/Au:N/C:N/I:C/A:C
Confidentiality
NONE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Ruby-LangRuby1.8.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-1004?

CVE-2011-1004 is a vulnerability with a CVSS score of 6.3 (MEDIUM). The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete...

How severe is CVE-2011-1004?

CVE-2011-1004 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-1004?

Check the references section above for vendor advisories and patch information. Affected products include: Ruby-Lang Ruby.