CVE-2009-4492
Last modified
CVE-2009-4492 is a vulnerability of currently unknown severity. WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.. EPSS estimates a 16.10% chance of exploitation in the next 30 days.
Description
WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruby-Lang | Webrick | 1.3.1 |
References
- http://secunia.com/advisories/37949Not Applicable, Vendor Advisory
- http://securitytracker.com/id?1023429Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.redhat.com/support/errata/RHSA-2011-0908.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0909.htmlThird Party Advisory
- http://www.ruby-lang.org/en/news/2010/01/10/webrick-escape-sequence-injectionPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/508830/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/37710Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.ush.it/team/ush/hack_httpd_escape/adv.txtBroken Link, Exploit
- http://www.vupen.com/english/advisories/2010/0089Permissions Required
- http://secunia.com/advisories/37949Not Applicable, Vendor Advisory
- http://securitytracker.com/id?1023429Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.redhat.com/support/errata/RHSA-2011-0908.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0909.htmlThird Party Advisory
- http://www.ruby-lang.org/en/news/2010/01/10/webrick-escape-sequence-injectionPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/508830/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/37710Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.ush.it/team/ush/hack_httpd_escape/adv.txtBroken Link, Exploit
- http://www.vupen.com/english/advisories/2010/0089Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4492?
How severe is CVE-2009-4492?
How do I fix CVE-2009-4492?
Are you affected by CVE-2009-4492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
