5
CVSSv2

CVE-2011-2705

Published: 05/08/2011 Updated: 19/01/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby prior to 1.8.7-p352 and 1.9.x prior to 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent malicious users to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.

Vulnerable Product Search on Vulmon Subscribe to Product

ruby-lang ruby 1.8.7

ruby-lang ruby

ruby-lang ruby 1.8.7-p21

ruby-lang ruby 1.8.7-173

ruby-lang ruby 1.8.7-160

ruby-lang ruby 1.8.7-330

ruby-lang ruby 1.8.7-249

ruby-lang ruby 1.8.7-248

ruby-lang ruby 1.8.7-302

ruby-lang ruby 1.8.7-299

ruby-lang ruby 1.9.1

ruby-lang ruby 1.9.0

ruby-lang ruby 1.9.0-2

ruby-lang ruby 1.9.0-20070709

ruby-lang ruby 1.9.0-1

ruby-lang ruby 1.9.2

ruby-lang ruby 1.9.2-p180

ruby-lang ruby 1.9

ruby-lang ruby 1.9.0-0

ruby-lang ruby 1.9.2-p136

ruby-lang ruby 1.9.0-20060415

Vendor Advisories

Several security issues were fixed in ruby18 ...
Synopsis Low: ruby security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic Updated ruby packages that fix two security issues, various bugs, and addone enhancement are now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having ...
Synopsis Moderate: ruby security update Type/Severity Security Advisory: Moderate Topic Updated ruby packages that fix two security issues are now available forRed Hat Enterprise Linux 4 and 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability Sc ...