High severity7.3NVD Advisory· Published Mar 29, 2017· Updated May 13, 2026
CVE-2009-5147
CVE-2009-5147
Description
DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
Affected products
23cpe:2.3:a:ruby-lang:ruby:1.8.0:*:*:*:*:*:*:*+ 22 more
- cpe:2.3:a:ruby-lang:ruby:1.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:1.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:1.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:1.9.3:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:p195:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:p247:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:p353:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:p481:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:p576:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:p594:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:p598:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:p643:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:p645:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.0.0:p647:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:ruby-lang:ruby:2.1.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- seclists.org/oss-sec/2015/q3/222nvdPatchThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryVDB Entry
- github.com/ruby/ruby/commit/4600cf725a86ce31266153647ae5aa1197b1215bnvdPatchThird Party Advisory
- www.securityfocus.com/bid/76060nvdThird Party AdvisoryVDB Entry
- www.ruby-lang.org/en/news/2015/12/16/unsafe-tainted-string-usage-in-fiddle-and-dl-cve-2015-7551/nvdVendor Advisory
- access.redhat.com/errata/RHSA-2018:0583nvd
News mentions
0No linked articles in our index yet.