CVE-2013-0162: Ryan Davis Ruby Parser

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.

Affected products

  • Ryan Davis Ruby Parser: up to and including 3.1.1; version 1.0.0 only; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; …

Published 2013-03-01. Last modified 2026-06-16.