>> Ruby Alias Functionality and Directory Operations Safe Level Security Bypass Vulnerabilities
Title : Ruby Alias Functionality and Directory Operations Safe Level Security Bypass Vulnerabilities VUPEN ID : VUPEN/ADV-2006-2760 CVE ID : CVE-2006-3694
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-12
Technical Description
Two vulnerabilities have been identified in Ruby, which could be exploited by attackers to bypass security restrictions.
The first issue is due to an error in the "alias" functionality, which could be exploited by attackers to bypass safe level restrictions.
The second flaw is due to improper validation of directory operations, which could be exploited by attackers to bypass safe level restrictions and close untainted directory streams.