VYPR
Unrated severityNVD Advisory· Published Jul 12, 2010· Updated Apr 29, 2026

CVE-2010-2489

CVE-2010-2489

Description

Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properly handled when constructing the filenames of the backup files.

Affected products

14
  • Ruby Lang/Ruby14 versions
    cpe:2.3:a:ruby-lang:ruby:1.9.0-0:*:*:*:*:*:*:*+ 13 more
    • cpe:2.3:a:ruby-lang:ruby:1.9.0-0:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.0-1:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.0-2:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.0-20060415:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.0-20070709:*:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.1:-p0:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.1:-p129:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.1:-p243:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.1:-p376:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.1:-p429:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.1:-preview_1:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.1:-preview_2:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.1:-rc1:*:*:*:*:*:*
    • cpe:2.3:a:ruby-lang:ruby:1.9.1:-rc2:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.