CVE-2009-4492
Publication date 13 January 2010
Last updated 24 July 2024
Ubuntu priority
WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window’s title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
Status
Package | Ubuntu Release | Status |
---|---|---|
ruby1.8 | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Not affected
|
|
10.04 LTS lucid |
Not affected
|
|
9.10 karmic | Ignored end of life | |
9.04 jaunty | Ignored end of life | |
8.10 intrepid | Ignored end of life, was needed | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life | |
ruby1.9 | 11.10 oneiric | Not in release |
11.04 natty | Not in release | |
10.10 maverick | Not in release | |
10.04 LTS lucid |
Fixed 1.9.0.5-1ubuntu2
|
|
9.10 karmic |
Fixed 1.9.0.5-1ubuntu1.2
|
|
9.04 jaunty |
Fixed 1.9.0.2-9ubuntu1.2
|
|
8.10 intrepid |
Fixed 1.9.0.2-7ubuntu1.3
|
|
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life | |
ruby1.9.1 | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Not affected
|
|
10.04 LTS lucid |
Not affected
|
|
9.10 karmic | Ignored end of life | |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release |
Notes
Patch details
Package | Patch details |
---|---|
ruby1.8 | |
ruby1.9 |