VDB
Sign up
LOW

GHSA-6x46-7rrv-m4h8

sqlite3-ruby uses weak permissions for unspecified files, which allows local users to gain privileges

Quick fix

GHSA-6x46-7rrv-m4h8 — sqlite3-ruby: upgrade to the fixed version with the command below.

bundle update sqlite3-ruby

Details

The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sqlite3-ruby
Introduced in: 0Fixed in: 1.2.4
Fixbundle update sqlite3-ruby

References