Wind River Support Network

HomeDefectsLIN8-7873
Fixed

LIN8-7873 : Security Advisory - ruby - CVE-2017-10784

Created: Sep 26, 2017    Updated: Dec 3, 2018
Resolved Date: Oct 27, 2017
Found In Version: 8.0.0.21
Fix Version: 8.0.0.23
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.

https://nvd.nist.gov/vuln/detail/CVE-2017-10784

Other Downloads


CVEs


Live chat
Online