5
CVSSv2

CVE-2012-2139

Published: 18/07/2012 Updated: 07/10/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in lib/mail/network/delivery_methods/file_delivery.rb in the Mail gem prior to 2.4.4 for Ruby allows remote malicious users to read arbitrary files via a .. (dot dot) in the to parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

rubygems mail gem

rubygems mail gem 2.4.1

rubygems mail gem 2.3.3

rubygems mail gem 2.3.2