RubySec

Providing security resources for the Ruby community

CVE-2011-0995 (sqlite3-ruby): rubygem-sqlite3 gem uses weak file permissions

ADVISORIES

GEM

sqlite3-ruby

SEVERITY

CVSS v2.0: 2.1 (Low)

PATCHED VERSIONS

  • >= 1.2.4

DESCRIPTION

The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.

RELATED