CVE-2012-4464: Ruby-Lang Ruby

Medium severity, CVSS 5.0. EPSS: 2.2% chance of exploitation in the next 30 days.

Ruby 1.9.3 before patchlevel 286 and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the (1) exc_to_s or (2) name_err_to_s API function, which marks the string as tainted, a different vulnerability than CVE-2012-4466. NOTE: this issue might exist because of a CVE-2011-1005 regression.

Affected products

  • Ruby-Lang Ruby: version 1.9.3 only; version 2.0 only; version 2.0.0 only

Published 2013-04-25. Last modified 2026-06-16.