CVE
- Id
- 62012
- CVE No.
- CVE-2013-2065
- Status
- Candidate
- Description
- (1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native functions, which allows context-dependent attackers to bypass intended $SAFE level restrictions.
- Phase
- Assigned (20130219)
- Votes
- None (candidate not yet proposed)
- Comments