Security Advisory

CVE-2009-4492

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-01-13 20:00:00
Last updated 2024-08-07 07:01:20
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.