DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "libruby1.9.1" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "libruby1.9.1-dbg" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "libruby1.9.1-dbgsym" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "libtcltk-ruby1.9.1" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "libtcltk-ruby1.9.1-dbgsym" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "ri1.9.1" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "ruby1.9.1" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "ruby1.9.1-dbgsym" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "ruby1.9.1-dev" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "ruby1.9.1-dev-dbgsym" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "ruby1.9.1-examples" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "ruby1.9.1-full" }, { "binary_version": "1.9.3.484-2ubuntu1.3", "binary_name": "ruby1.9.3" } ] }