CVE

Id
62012  
CVE No.
CVE-2013-2065  
Status
Candidate  
Description
(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native functions, which allows context-dependent attackers to bypass intended $SAFE level restrictions.  
Phase
Assigned (20130219)  
Votes
None (candidate not yet proposed)  
Comments