ruby-lang ruby CVE-2011-2686 is a vulnerability in Ruby Programming Language Ruby Language
Published on August 5, 2011

Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900. NOTE: this issue exists because of a regression during Ruby 1.8.6 development.

Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2011-2686

Want to know whenever a new CVE is published for Ruby Programming Language Ruby Language? stack.watch will email you.

 

Exploit Probability

EPSS
0.67%
Percentile
70.95%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.