« Volver al listado

CVE-2010-2489

Estado: ModificadaAlta (7.2)—

Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properly handled when constructing the filenames of the backup files.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-2489",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-07-12T13:27:27.813",
  "references": [
    {
      "url": "http://osdir.com/ml/ruby-talk/2010-07/msg00095.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/40442",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://svn.ruby-lang.org/repos/ruby/tags/v1_9_1_429/ChangeLog",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://svn.ruby-lang.org/repos/ruby/tags/v1_9_2_rc1/ChangeLog",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/07/02/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/07/02/10",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.osvdb.org/66040",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.ruby-lang.org/en/news/2010/07/02/ruby-1-9-1-p429-is-released/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/41321",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/60135",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://osdir.com/ml/ruby-talk/2010-07/msg00095.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/40442",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://svn.ruby-lang.org/repos/ruby/tags/v1_9_1_429/ChangeLog",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://svn.ruby-lang.org/repos/ruby/tags/v1_9_2_rc1/ChangeLog",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/07/02/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/07/02/10",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/66040",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ruby-lang.org/en/news/2010/07/02/ruby-1-9-1-p429-is-released/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/41321",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/60135",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properly handled when constructing the filenames of the backup files."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer en Ruby v1.9.x anterior v1.9.1-p429 en Windows puede permitir a usuarios locales ganar privilegios mediante un valor ARGF.inplace_mode manipulado que no es correctamente manejado cuando construye los nombres de archivos de los ficheros backup"
    }
  ],
  "lastModified": "2026-06-16T23:20:50.930",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.0-0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2D5127F-1E79-4F83-8BB0-C479B6CFE9AE"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.0-1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31181BA2-71A7-40C8-9E08-8FEAB013977B"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.0-2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB8F3772-C973-41DB-AB3A-F4323418FC7F"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.0-20060415:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A688B357-7096-4362-A7DD-5A24FB0AF431"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.0-20070709:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46913DE9-8AE6-40E5-AEA1-6D2524EE7581"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.1:-p0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "470CF526-96F6-4DD1-B687-17106051A6D5"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.1:-p129:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52159D9F-8CD3-4103-82E6-BDE035BA3625"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.1:-p243:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC0FD3F8-73A3-4518-8892-1E34D709FB89"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.1:-p376:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B846CCE-7D1D-4A7E-95D8-50F92CF79AC6"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.1:-p429:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB99DD31-7355-4FF1-AE41-CC156F83D7A2"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.1:-preview_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7E15263-74D3-42D4-B37C-C649F68EDECC"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.1:-preview_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA7FEA9B-06CE-4D08-9D61-2526ED5AE630"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.1:-rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D7F7EA5-7F6C-4C15-AB97-024836DC4862"
            },
            {
              "criteria": "cpe:2.3:a:ruby-lang:ruby:1.9.1:-rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "236B38D1-0CCA-43C5-B2FC-1224F4F4E165"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}