CVE-2013-0162 PUBLISHED

The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.

EPSS 0.15% · 35.3th percentile

Risk Scores

EPSS Score
0.15%
35.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSruby-parser0, 3.6.6-1
Ubuntu:18.04:LTSruby-parser0, 3.8.2-1
Ubuntu:20.04:LTSruby-parser0, 3.11.0-1

Timeline

References

Open in Interactive Console →