Description
The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-5820 Vulnerability (CVE-2013-5820)
MySQL CVE-2016-5440 Vulnerability (CVE-2016-5440)
WordPress Plugin Log Emails Information Disclosure (1.0.6)
WordPress Plugin Store Locator Plus for WordPress Privilege Escalation (5.5.14)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0346)