RubySec

Providing security resources for the Ruby community

CVE-2014-5002 (lynx): lynx Gem for Ruby command/basic.rb Process Table Local Plaintext Password Disclosure

lynx Gem for Ruby command/basic.rb Process Table Local Plaintext Password Disclosure

Published: June 30, 2014

SECURITY IDENTIFIERS

GEM

lynx

SEVERITY

CVSS v3.x: 7.8 (High)

PATCHED VERSIONS

>= 1.0.0

DESCRIPTION

lynx Gem for Ruby contains a flaw in command/basic.rb that is due to the application exposing password information in plaintext in the process table. This may allow a local attacker to gain access to password information.