Name | CVE-2006-3694 |
Description | Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations". |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1139-1, DSA-1157 |
Debian Bugs | 378029 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
ruby1.6 | source | sarge | 1.6.8-12sarge2 | DSA-1139-1 | ||
ruby1.8 | source | sarge | 1.8.2-7sarge4 | DSA-1157 | ||
ruby1.8 | source | (unstable) | 1.8.4-3 | medium | 378029 | |
ruby1.9 | source | (unstable) | 1.9.0+20060609-1 | medium |