Inclusion of Functionality from Untrusted Control Sphere
CVE-2013-1945
Summary
ruby193 uses an insecure LD_LIBRARY_PATH setting.
- LOW
- LOCAL
- LOW
- UNCHANGED
- NONE
- LOW
- NONE
- NONE
CWE-829 - Inclusion of Functionality from Untrusted Control Sphere
The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
References
Advisory Timeline
- Published