MEDIUM
GHSA-6mq2-37j5-w6r6
WEBrick Improper Input Validation vulnerability
Quick fix
GHSA-6mq2-37j5-w6r6 — webrick: upgrade to the fixed version with the command below.
bundle update webrickDetails
WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2009-4492[ADVISORY]
- https://github.com/advisories/GHSA-6mq2-37j5-w6r6[ADVISORY]
- https://github.com/ruby/webrick[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/webrick/CVE-2009-4492.yml[WEB]
- https://web.archive.org/web/20100113155532/http://www.vupen.com/english/advisories/2010/0089[WEB]
- https://web.archive.org/web/20100815010948/http://secunia.com/advisories/37949[WEB]
- https://web.archive.org/web/20170402100552/http://securitytracker.com/id?1023429[WEB]
- https://web.archive.org/web/20170908140655/http://www.securityfocus.com/archive/1/508830/100/0/threaded[WEB]
- https://web.archive.org/web/20200228145937/http://www.securityfocus.com/bid/37710[WEB]
- http://www.redhat.com/support/errata/RHSA-2011-0908.html[WEB]
- http://www.redhat.com/support/errata/RHSA-2011-0909.html[WEB]
- http://www.ruby-lang.org/en/news/2010/01/10/webrick-escape-sequence-injection[WEB]
- http://www.ush.it/team/ush/hack_httpd_escape/adv.txt[WEB]