LOW
GHSA-6x46-7rrv-m4h8
sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges
Quick fix
GHSA-6x46-7rrv-m4h8 — sqlite3-ruby: upgrade to the fixed version with the command below.
bundle update sqlite3-rubyDetails
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2011-0995[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67263[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sqlite3-ruby/CVE-2011-0995.yml[WEB]
- https://github.com/schuyler/sqlite3-ruby[PACKAGE]
- https://web.archive.org/web/20110513184951/http://support.novell.com/security/cve/CVE-2011-0995.html[WEB]
- https://web.archive.org/web/20200229151908/http://www.securityfocus.com/bid/47694[WEB]
- https://web.archive.org/web/20201106213407/https://bugzilla.novell.com/show_bug.cgi?id=685928[WEB]
- https://www.suse.com/security/cve/CVE-2011-0995.html[WEB]